{"id":2287,"date":"2026-07-23T12:30:13","date_gmt":"2026-07-23T12:30:13","guid":{"rendered":"https:\/\/forecastingresearch.org\/?post_type=research&#038;p=2287"},"modified":"2026-07-23T12:35:04","modified_gmt":"2026-07-23T12:35:04","slug":"ai-cyber-risks-capabilities","status":"publish","type":"research","link":"https:\/\/forecastingresearch.org\/research\/ai-cyber-risks-capabilities","title":{"rendered":"Forecasting AI Cyber Risks  and Capabilities: Results of a 2025 Pilot Study"},"content":{"rendered":"\n<div class=\"wp-block-group\"><div class=\"wp-block-group__inner-container is-layout-constrained wp-block-group-is-layout-constrained\">\n<details class=\"wp-block-details is-layout-flow wp-block-details-is-layout-flow\"><summary>Acknowledgments<\/summary>\n<p class=\"wp-block-paragraph\">This research would not have been possible without the support of Coefficient Giving or the thoughtful participation of our survey respondents. We are grateful to Luca Righetti for feedback on the survey and research design, and to Victoria Schmidt and Amory Bennett for assistance with survey design.<\/p>\n<\/details>\n\n\n\n<details class=\"wp-block-details is-layout-flow wp-block-details-is-layout-flow\"><summary>Disclaimers<\/summary>\n<p class=\"wp-block-paragraph\">This report is based on forecasts from a survey conducted primarily in July and August 2025, with follow-up responses collected between December 2025 and January 2026. Because AI-cyber capabilities are changing rapidly, the results should not be interpreted as a current assessment of frontier-model cyber capabilities. In particular, at the time of the survey, Claude Mythos Preview\/Mythos 5, Claude Fable 5, GPT\u20115.3\u2011Codex, GPT\u20115.5\/GPT-5.6\/GPT\u20115.5\u2011Cyber and other cyber-specialized models had not been deployed.<\/p>\n<\/details>\n<\/div><\/div>\n\n\n\n<h2 id=\"executive-summary\" class=\"wp-block-heading\">Executive Summary<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">This pilot study, conducted primarily in July and August 2025, investigated how AI capabilities may affect near-term cybersecurity risk. Using structured forecasting with 21 participants\u201413 superforecasters and eight cybersecurity experts\u2014we examined two high-impact cyberattack pathways in 2026:<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li><strong>Data-damaging worm attacks<\/strong>, similar to WannaCry and NotPetya, that could cause at least $10 billion in economic damages.<\/li>\n\n\n\n<li><strong>Cyberattacks against the U.S. electrical grid<\/strong> that cause large-scale blackouts with at least $10 billion or at least $100 billion in economic damages.<\/li>\n<\/ul>\n\n\n\n<p class=\"wp-block-paragraph\">Participants provided responses to the survey between <strong>July 23<sup>rd<\/sup> and August 29<sup>th<\/sup>, 2025<\/strong> and some participants responded to a follow-up survey between December 11<sup>th<\/sup>, 2025 and January 6<sup>th<\/sup>, 2026. Because the study was designed as a pilot, the results should be interpreted as initial evidence for areas that merit further research, not as definitive estimates. Even so, the forecasts show a consistent pattern: participants assessed baseline risks of catastrophic cyber harms in 2026 as low but non-negligible, and they expected some AI capabilities to substantially increase those risks, especially when AI lowers barriers for moderate-sophistication actors.<\/p>\n\n\n\n<h3 id=\"key-findings\" class=\"wp-block-heading\">Key findings<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>Data-damaging worms were assessed as the higher-risk pathway.<\/strong> Participants estimated a 5\u20138% probability of at least one data-damaging worm attack causing at least $10 billion in damages in 2026. The median participant\u2019s forecast of expected annual damages from data-damaging worms was approximately $10\u201315 billion.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>Electrical-grid cyberattack risks were assessed as substantially lower.<\/strong> Participants estimated a 1% probability that a cyberattack against the U.S. electrical grid would cause at least $10 billion in damages in 2026, and a 0.1% probability that such an attack would cause at least $100 billion in damages. Expected annual damages were roughly $0.2\u20131 billion, more than an order of magnitude lower than for worms.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>AI-enabled elite exploit development produced the largest risk increase.<\/strong> Under a hypothetical scenario in which AI models enable 25% of moderately-skilled individual hackers to find vulnerabilities and write elite exploits, and models with this capability are available open-weight, worm attack risk estimates increase by 3\u20133.5x. The median expert forecast of a data-damaging worm attack causing at least $10 billion in damages rose from 8% to 41%, while the median superforecaster forecast rose from 5% to 15%.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>AI-cyber progress has already outpaced participants\u2019 forecasts.<\/strong> Participants generally expected the most relevant capabilities to emerge after 2026. Yet, since the survey closed in summer 2025, frontier models have very likely crossed the 90% threshold on Cybench, with one later reaching 100% on a subset of tasks. Recent model evaluations also suggest rapid movement towards AI-enabled exploit development capabilities, the capability that was of greatest concern to forecasters. These developments imply a shorter window for model testing, release safeguards, and defensive planning than the original forecasts suggested.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>Current cyber benchmarks may be informative, but they are imperfect signals of real-world cyber risk.<\/strong> Participants generally saw AI performance on Cybench as informative of technical progress, but not as the best standalone indicator of whether capabilities most relevant to catastrophic cyber outcomes, such as elite exploit development or real-world grid attacks, had been achieved. Respondents generally viewed current benchmarks as incomplete measures of operational constraints such as zero-day discovery, targeting, coordination, and persistence. Current cyber evaluations may track important technical progress without fully measuring the forms of AI-enabled uplift most relevant to real-world cyber risks.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>Model access controls were seen as meaningful but incomplete mitigations.<\/strong> Nearly half of the participants thought that keeping the relevant models\u2014those that could enable moderate-sophistication actors to develop elite exploits\u2014proprietary and protected by anti-jailbreaking measures would at least halve the risk of a large-scale worm attack. However, participants also noted that such measures may be less effective against sophisticated actors, or exploit-as-a-service markets.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>In a follow-up survey conducted four months later, forecasts remained largely unchanged.<\/strong> A subset of participants revisited some of their forecasts between December 2025 and January 2026, after reviewing the original study results and Anthropic\u2019s report on an AI-assisted cyber espionage campaign.<sup data-fn=\"58fc9118-26c1-4962-abb0-631b2d38f0fe\" class=\"fn\"><a href=\"#58fc9118-26c1-4962-abb0-631b2d38f0fe\" id=\"58fc9118-26c1-4962-abb0-631b2d38f0fe-link\">1<\/a><\/sup> The median forecast for a data-damaging worm attack causing at least $10 billion in damages in 2026 remained unchanged. Many participants thought the Anthropic report suggested that actors were more capable than they had originally expected, but most did not view it as direct evidence that AI could develop elite exploits or execute a large-scale data-damaging worm by 2026.<\/p>\n\n\n\n<figure class=\"wp-block-table\"><div class=\"table-wrapper\"><table class=\"has-fixed-layout\"><tbody><tr><td><strong>Threat model<\/strong><\/td><td><strong>Baseline \u2265$10B probability<\/strong><\/td><td><strong>Baseline expected damages<\/strong><\/td><td><strong>Main AI impact result<\/strong><\/td><\/tr><tr><td>Data-damaging worm<\/td><td><p>Experts: 8%<\/p>\n<p>Superforecasters: 5%<\/p><\/td><td><p>Experts: ~$15B<\/p>\n<p>Superforecasters: ~$10B<\/p><\/td><td>Capability 1 (AI enables moderately-skilled individual hackers to develop elite exploits) raises the risk to 41% for experts and 15% for superforecasters. Expected damages increase by ~3\u20135x.<\/td><\/tr><tr><td>U.S. electrical grid cyberattack<\/td><td><p>Experts: 1%<\/p>\n<p>Superforecasters: 1%<\/p><\/td><td><p>Experts: $0.2B<\/p>\n<p>Superforecasters: $1B<\/p><\/td><td>Uplift in an ICS\/OT capture-the-flag has only modest effect. An AI-enabled $100M warning shot raises risk to 15% for experts and 4% for superforecasters.<\/td><\/tr><\/tbody><\/table><\/div><figcaption class=\"wp-element-caption\"><strong>Table 1:<\/strong> Summary of 2026 risk forecasts by threat model<\/figcaption><\/figure>\n\n\n\n<div class=\"wp-block-buttons is-layout-flex wp-block-buttons-is-layout-flex\">\n<div class=\"wp-block-button\"><a class=\"btn orange\" href=\"https:\/\/forecastingresearch.org\/pdf\/ai-cyber-risks-capabilities.pdf\" target=\"_blank\" rel=\"noreferrer noopener\">View the full PDF report <svg width=\"7\" height=\"9\" viewBox=\"0 0 7 9\" fill=\"none\" xmlns=\"http:\/\/www.w3.org\/2000\/svg\">\n  <path d=\"M0.000156283 8.60806L4.22416 4.33606V4.24006L0.000156283 6.10352e-05H1.80816L6.06416 4.28806L1.80816 8.60806H0.000156283Z\" fill=\"#102B23\"\/>\n<\/svg>\n<svg width=\"8\" height=\"10\" viewBox=\"0 0 8 10\" fill=\"none\" xmlns=\"http:\/\/www.w3.org\/2000\/svg\">\n  <path d=\"M0.601719 8.85794L4.82572 4.58594V4.48994L0.601719 0.249939H2.40972L6.66572 4.53794L2.40972 8.85794H0.601719Z\" fill=\"#102B23\"\/>\n<\/svg><\/a><\/div>\n<\/div>\n\n\n\n<h3 id=\"data-damaging-worms-main-takeaways\" class=\"wp-block-heading\">Data-damaging worms: main takeaways<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">The median expert forecasted an 8% probability that a large-scale data-damaging worm attack would cause at least $10 billion in economic damages in 2026, while the median superforecaster forecasted a 5% probability. These baseline forecasts were anchored by the low historical frequency of cyberattacks of this magnitude. However, participants noted that the 2017 WannaCry and NotPetya worm attacks demonstrate that worms can spread rapidly, and that future attacks could have large impacts in a more digitally dependent economy. Expected damages were approximately $10\u201315 billion.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">The main bottleneck identified in this threat model was the development of elite exploits; powerful software exploits that can spread without user interaction, enable high-privilege remote code execution, and work against widely used software. In agreement with this, AI-enabled elite exploit development was seen as a significant driver of increased risk. If an open-weight AI model enabled 25% of moderately-skilled individual hackers to find vulnerabilities and write elite exploits, the median expert forecast rose to 41% and the median superforecaster forecast to 15%. Participants viewed this as an important risk pathway because individual hackers are relatively numerous and may be more willing to cause damage, but they are usually capability-constrained; more sophisticated actors are generally more capable but constrained by escalation and retaliation risks.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Participants expected model-access controls and safeguards to reduce this risk, especially for actors below state-level sophistication, but not to eliminate it. In particular, having models with the relevant capabilities protected with anti-jailbreak measures was believed to significantly decrease the probability of a large-scale data-damaging worm attack. Model-weight theft, exploit-as-a-service markets, and slow patching of vulnerabilities remained important limitations.<\/p>\n\n\n\n<figure class=\"wp-block-image size-full\" id=\"fig-01\"><img decoding=\"async\" src=\"https:\/\/forecastingresearch.org\/wp-content\/uploads\/2026\/07\/paper_2026-07-07_ai-cyber-risks-capabilities_fig-01.png\" alt=\"\"\/><figcaption class=\"wp-element-caption\"><strong>Figure 1:<\/strong> Forecasts of the probability of at least one data-damaging worm attack causing at least $10 billion in economic damages in 2026, under baseline assumptions, and conditional on AI capabilities and potential mitigations.<\/figcaption><\/figure>\n\n\n\n<h3 id=\"electrical-grid-cyberattacks-main-takeaways\" class=\"wp-block-heading\">Electrical grid cyberattacks: main takeaways<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">Participants assessed large-scale cyberattacks against the U.S. grid in 2026 as substantially less likely than data-damaging worm attacks. The median expert and superforecaster both put the probability of a cyberattack against the grid causing at least $10 billion in damages at 1%; for a larger attack, causing at least $100 billion, both medians were 0.1%. Expected annual damages were also much lower, at approximately $0.2\u20131 billion.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Participants emphasized that grid attacks face additional barriers beyond cyber capability, including expertise in industrial control systems (ICS), operational coordination, physical infrastructure constraints, and geopolitical escalation risks. They generally viewed a large-scale grid attack as more likely in the context of war, or a state-level conflict, than as ordinary cybercrime.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Forecasts of large-scale cyberattacks against the U.S. electrical grid were less sensitive to AI capability scenarios than forecasts in the data-damaging worm threat model. AI uplift on an ICS\/OT (operational technology) capture-the-flag style competition only modestly increased the median forecast from 1% to 1.5\u20132%. A real-world AI-enabled warning shot causing at least $100 million in damages produced a larger increase in risk, raising the median forecast to 15% among experts and 4% among superforecasters. Overall, results from this pilot suggest that AI may increase risk associated with this threat model, but large-scale grid attacks remain constrained by operational complexity and geopolitical considerations.<\/p>\n\n\n\n<figure class=\"wp-block-image size-full\" id=\"fig-02\"><img decoding=\"async\" src=\"https:\/\/forecastingresearch.org\/wp-content\/uploads\/2026\/07\/paper_2026-07-07_ai-cyber-risks-capabilities_fig-02.png\" alt=\"\"\/><figcaption class=\"wp-element-caption\"><strong>Figure 2:<\/strong> Forecasts of the probability of at least one cyberattack against the U.S. electrical grid causing at least $10 billion in economic damages in 2026, under baseline assumptions, and conditional on Capability 3 (AI enables TA1 actors to perform like a TA3 actor in an OT-specific capture-the-flag style competition) and Capability 4 (a real-world warning shot incident).<\/figcaption><\/figure>\n\n\n\n<h2 id=\"introduction\" class=\"wp-block-heading\">Introduction<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">Rapid advances in artificial intelligence capabilities have introduced new dimensions of uncertainty into the cybersecurity landscape. As frontier AI systems become increasingly sophisticated in their ability to identify vulnerabilities, write code, and automate complex tasks, questions arise about how these capabilities might alter the cyber threat environment. AI could strengthen defenders by supporting vulnerability discovery, patch development, threat detection, and incident response. It could also benefit attackers by reducing the skill, time, and coordination required to identify vulnerabilities, develop exploits, and scale attacks. A central uncertainty is whether AI will strengthen defensive capabilities overall, disproportionately benefit malicious actors, or affect different threat actors in different ways.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">This pilot study is an initial effort to systematically forecast how AI might affect large-scale cyber risks over the near term, with a particular focus on 2026. We used structured forecasting methods to elicit judgments about two high-impact cyber threat scenarios: data-damaging worm attacks and cyberattacks against the United States (U.S.) electrical grid.<\/p>\n\n\n\n<h3 id=\"background\" class=\"wp-block-heading\">Background<\/h3>\n\n\n\n<h4 id=\"data-damaging-worms\" class=\"wp-block-heading\">Data-damaging worms<\/h4>\n\n\n\n<p class=\"wp-block-paragraph\">A \u201cworm\u201d is malware that can spread autonomously between systems without an attacker needing to infect each system individually. Worms can cause damage in several ways. In this survey, we focused on \u201cdata-damaging worms\u201d: worms that directly damage\u2013by wiping, encrypting, or corrupting it\u2013on a large number of systems. Relevant historical examples include <a href=\"https:\/\/en.wikipedia.org\/wiki\/WannaCry_ransomware_attack\" target=\"_blank\" rel=\"noreferrer noopener\">WannaCry<\/a> and <a href=\"https:\/\/www.sipa.columbia.edu\/sites\/default\/files\/2022-11\/NotPetya%20Final.pdf\" target=\"_blank\" rel=\"noreferrer noopener\">NotPetya<\/a>, both released in 2017, which are estimated to have caused roughly $1B\u2013$10B in damage after infecting and damaging hundreds of thousands of systems.<sup data-fn=\"f890f4e9-8073-489c-9d19-5240c47094e0\" class=\"fn\"><a href=\"#f890f4e9-8073-489c-9d19-5240c47094e0\" id=\"f890f4e9-8073-489c-9d19-5240c47094e0-link\">2<\/a><\/sup><\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Worm attacks can exploit vulnerabilities: bugs in software or hardware that create security weaknesses in the design, implementation, or operation of a system or application. An exploit is malicious code that takes advantage of one or more software vulnerabilities to infect, disrupt, or take control of a computer without the user\u2019s consent and typically without their knowledge. We define exploits (or exploit chains) as \u201celite\u201d if they satisfy all of the following criteria:<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li><strong>Zero-click:<\/strong> Infection requires no user interaction, such as opening emails, clicking links or visiting a webpage<\/li>\n\n\n\n<li><strong>Remote code execution:<\/strong> Allow attackers to execute arbitrary code on a system without the user\u2019s knowledge, and without attackers requiring physical access to the system<\/li>\n\n\n\n<li><strong>High privileges:<\/strong> Have administrator privileges or higher.<\/li>\n\n\n\n<li><strong>Targets widely used software:<\/strong> Effective against more than 10 million systems.<\/li>\n<\/ul>\n\n\n\n<p class=\"wp-block-paragraph\">Elite exploits are especially well-suited to worm attacks as they enable autonomous spread and significant damage on a large number of systems. The leak of elite exploits initially developed by the NSA in 2017 quickly led to the two major data-damaging worm attacks cited above: WannaCry and NotPetya. Developing elite exploits may require an order of magnitude more skilled researcher time than the other tasks involved in developing a data-damaging worm.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Table 2 below uses data adapted from Johansmeyer (2024) and provides details on past major worm attacks.<sup data-fn=\"8487a169-7812-45cb-b769-6d626cec49cd\" class=\"fn\"><a href=\"#8487a169-7812-45cb-b769-6d626cec49cd\" id=\"8487a169-7812-45cb-b769-6d626cec49cd-link\">3<\/a><\/sup> Here, \u201cmajor worm attacks\u201d are attacks that affected more than 10-25 companies, and for which at least one source claims damages of more than $800M.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Where this table and later results refer to TA1\u2013TA5 actors, these labels denote classes of threat actors in terms of sophistication, or <em>operational capacity<\/em> (OC)<em>.<\/em> These categories are ordered by ascending capability: TA1 actors are assessed as able to carry out OC1 operations, TA2 actors are able to carry out OC2 operations, and so on up to TA5. These categories are based on the five levels of cyberattack operational capacity defined by RAND.<sup data-fn=\"94e3079e-6b1a-45c2-b494-b8abeaf8a3b2\" class=\"fn\"><a href=\"#94e3079e-6b1a-45c2-b494-b8abeaf8a3b2\" id=\"94e3079e-6b1a-45c2-b494-b8abeaf8a3b2-link\">4<\/a><\/sup> By definition, each category includes the capacities of all preceding categories. For example, the most capable nation-states, such as the U.S. and China, are able to carry out OC5 operations and all operations below that level. <a href=\"https:\/\/forecastingresearch.org\/wp-content\/uploads\/pdf\/ai-cyber-risks-capabilities.pdf#page=49\" target=\"_blank\" rel=\"noreferrer noopener\">Appendix A<\/a> provides the full definitions.<\/p>\n\n\n\n<figure class=\"wp-block-table\"><div class=\"table-wrapper\"><table class=\"has-fixed-layout\"><tbody><tr><td><strong>Attack name<\/strong><\/td><td><strong>Year<\/strong><\/td><td><strong>Actor<\/strong><\/td><td><strong>Description<\/strong><\/td><td><strong># Infections<\/strong><\/td><td><strong>Elite exploit?<\/strong><\/td><td><p><strong>Data-<\/strong><strong style=\"font-size: revert; font-family: inherit;\">damaging worm?<\/strong><\/p><\/td><\/tr><tr><td>Melissa<\/td><td>1999<\/td><td>TA1\/2<\/td><td>Email worm. Damage via high network traffic, no other destructive payload<\/td><td>~100K<\/td><td>N<\/td><td>N<\/td><\/tr><tr><td>ILOVEYOU<\/td><td>2000<\/td><td>TA1\/2<\/td><td>Email worm. Corrupted documents, later variant wiped hard drive.<\/td><td>~50M<\/td><td>N<\/td><td>Y<\/td><\/tr><tr><td>Klez<\/td><td>2001<\/td><td>TA1\/2?<\/td><td>Email worm. Damage via high network traffic and disabling antivirus<\/td><td>~7M<\/td><td>N<\/td><td>N<\/td><\/tr><tr><td>CodeRed<\/td><td>2001<\/td><td>?<\/td><td>Zero-click. Defaced specific websites and launched targeted denial of service attacks against sites<\/td><td>~360K<\/td><td>N<\/td><td>N<\/td><\/tr><tr><td>Nimda<\/td><td>2001<\/td><td>?<\/td><td>Zero-click + email spread. Damage via high network traffic and elevated privileges<\/td><td>&gt;1.3M<\/td><td>Y<\/td><td>N<\/td><\/tr><tr><td>SirCam<\/td><td>2001<\/td><td>TA1\/2?<\/td><td>Email worm. Could expose confidential info, and delete all files in certain conditions<\/td><td>~2.3M<\/td><td>N<\/td><td>Y<\/td><\/tr><tr><td>SoBig<\/td><td>2003<\/td><td>TA1\/2?<\/td><td>Email worm to distribute spam. Also caused damage by creating high network traffic<\/td><td>&gt;1M<\/td><td>N<\/td><td>N<\/td><\/tr><tr><td>SQL Slammer<\/td><td>2003<\/td><td>TA1\/2?<\/td><td>Zero-click, but limited reach. Damage via high network traffic, no malicious payload<\/td><td>&gt;75K<\/td><td>N<\/td><td>N<\/td><\/tr><tr><td>Swen<\/td><td>2003<\/td><td>?<\/td><td>Email worm. Disabled antivirus and firewalls, no other destructive payload<\/td><td>~1.5M<\/td><td>N<\/td><td>N<\/td><\/tr><tr><td>Mimail<\/td><td>2003<\/td><td>?<\/td><td>Email worm. Launched targeted denial of service attacks against anti-spam sites. Some variants stole credit card information<\/td><td>~21K<\/td><td>N<\/td><td>N<\/td><\/tr><tr><td>Yaha<\/td><td>2003<\/td><td>TA3<\/td><td>Email worm. Terminated security processes and launched denial of service attacks<\/td><td>?<\/td><td>N<\/td><td>N<\/td><\/tr><tr><td>MyDoom<\/td><td>2004<\/td><td>TA1\/2?<\/td><td>Email worm. Created botnet to allow targeted denial of service attacks. Created high network traffic<\/td><td>~500K<\/td><td>N<\/td><td>N<\/td><\/tr><tr><td>Sasser<\/td><td>2004<\/td><td>TA1\/2<\/td><td>Zero-click. Damage only via large volumes of network traffic, no malicious payload<\/td><td>~500K\u20131M<\/td><td>Y<\/td><td>N<\/td><\/tr><tr><td>Storm Worm<\/td><td>2007<\/td><td>TA3<\/td><td>Spread via email and social engineering. Created denial of service botnet to attack groups<\/td><td>1M-50M<\/td><td>N<\/td><td>N<\/td><\/tr><tr><td>Conficker<\/td><td>2008<\/td><td>TA3<\/td><td>Zero-click. Created large botnet, but never used for significant attack due to concern about criminal repercussions<\/td><td>~10M<\/td><td>Y<\/td><td>N<\/td><\/tr><tr><td>WannaCry<\/td><td>2017<\/td><td>TA4<\/td><td>Zero-click. Encrypted files. Ransomware apparently to raise money for North Korea<\/td><td>~230K<\/td><td>Y<\/td><td>Y<\/td><\/tr><tr><td>NotPetya<\/td><td>2017<\/td><td>TA5<\/td><td>Zero-click. Encrypted files. Designed to limit damage to Ukraine<\/td><td>~670K<\/td><td>Y<\/td><td>Y<\/td><\/tr><\/tbody><\/table><\/div><figcaption class=\"wp-element-caption\"><strong>Table 2:<\/strong> Past major worm attacks: descriptions, approximate infections, exploit type, and data-damaging status.<\/figcaption><\/figure>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>In recent years, the number of major worm attacks has steeply declined<\/strong>, and worm attacks have been released by more sophisticated actors. It is plausible that these trends were driven by improvements in cybersecurity (for example in email filtering technology, patching practices, and malware detection systems) over time. These ongoing improvements may make it harder to cause substantial damage with worms today.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">The effect of AI on the risk of worm attacks is uncertain and likely to vary over time. AI systems that can discover vulnerabilities, develop exploits, or automate attack steps are dual-use: the same capabilities could help both defenders and attackers. The net effect depends on several uncertain factors, including which actors gain access to the most capable models, how quickly vulnerabilities are disclosed and patched, and whether patch deployment keeps pace with discovery.<\/p>\n\n\n\n<h4 id=\"cyberattacks-against-the-u.s.-electrical-grid\" class=\"wp-block-heading\">Cyberattacks against the U.S. electrical grid<\/h4>\n\n\n\n<p class=\"wp-block-paragraph\">The power grid consists of generators, transmission and distribution networks, and substations. Grid operations, like other infrastructure and industrial processes, rely on two broad types of computer systems:<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li><strong>Information technology (IT) systems:<\/strong> systems that handle most business operations like billing, email, and administration, and are typically connected to the internet.<\/li>\n\n\n\n<li><strong>Operational technology (OT) systems:<\/strong> programmable systems that interact with the physical environment or manage devices that do. In grid operations, these systems will monitor and control equipment like generators, circuit breakers, and transformers.<\/li>\n<\/ul>\n\n\n\n<p class=\"wp-block-paragraph\">Grid cyberattacks will involve compromising OT systems, since this is a precondition for interfering directly with grid behavior. OT environments, when compared to IT environments, present additional challenges. They typically are\u2014or should be\u2014segmented from IT and internet-facing networks,<sup data-fn=\"7d6f06f0-962a-456f-a032-fb65d7b4b753\" class=\"fn\"><a href=\"#7d6f06f0-962a-456f-a032-fb65d7b4b753\" id=\"7d6f06f0-962a-456f-a032-fb65d7b4b753-link\">5<\/a><\/sup> and they use more niche software and protocols requiring more specialized knowledge; OT devices may have relatively individualized configurations to a given environment.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">In this study, we focused on major blackouts: large-scale outages affecting hundreds of thousands of customers or more. There is less historical data on large-scale grid cyberattacks than on many other cyber threats. Examining databases of prior cyberattacks, including <a href=\"https:\/\/csis-website-prod.s3.amazonaws.com\/s3fs-public\/2024-12\/241210_Significant_Cyber_Events.pdf?VersionId=6M4z53qCe64xZ4cFQd7nkkTFPrQmeLPB\" target=\"_blank\" rel=\"noreferrer noopener\">CSIS<\/a>, <a href=\"https:\/\/www.cfr.org\/cyber-operations\/\" target=\"_blank\" rel=\"noreferrer noopener\">CFR<\/a>, and <a href=\"https:\/\/cissm.umd.edu\/research-impact\/publications\/cyber-events-database-home\" target=\"_blank\" rel=\"noreferrer noopener\">CISSM<\/a>, identified only three instances in which cyberattacks against the grid caused power outages, all of which occurred in Ukraine. There are many more cases of grid cyberattacks that did not result in outages but did cause other disruptions, such as temporary loss of operator visibility or control over grid equipment. Between 2010 and 2022, U.S. utilities reported roughly four disturbances per year due to cyberattacks\u2014to our knowledge, none of these have resulted in outages.<sup data-fn=\"4bad6543-932d-43e8-979a-cdfdecc05ff5\" class=\"fn\"><a href=\"#4bad6543-932d-43e8-979a-cdfdecc05ff5\" id=\"4bad6543-932d-43e8-979a-cdfdecc05ff5-link\">6<\/a><\/sup> Table 3 gives more details on past grid cyberattacks.<\/p>\n\n\n\n<figure class=\"wp-block-table\"><div class=\"table-wrapper\"><table class=\"has-fixed-layout\"><tbody><tr><td><strong>Location<\/strong><\/td><td><strong>Year<\/strong><\/td><td><strong>Actor<\/strong><\/td><td><strong>Details<\/strong><\/td><td><strong>Blackout<\/strong><\/td><\/tr><tr><td>Ukraine<\/td><td>2015<\/td><td>TA5<\/td><td>Attack on distribution substations caused ~3.5h outage for 225k customers<\/td><td>Y<\/td><\/tr><tr><td>Ukraine<\/td><td>2016<\/td><td>TA5<\/td><td>Attack on transmission substation caused ~1h outage of similar scope<\/td><td>Y<\/td><\/tr><tr><td>US<\/td><td>2018<\/td><td>?<\/td><td>Brief loss of control\/view over generation assets<sup data-fn=\"277dd50e-c636-465c-b1e8-45d4864d89fa\" class=\"fn\"><a href=\"#277dd50e-c636-465c-b1e8-45d4864d89fa\" id=\"277dd50e-c636-465c-b1e8-45d4864d89fa-link\">7<\/a><\/sup><\/td><td>N<\/td><\/tr><tr><td>US<\/td><td>2019<\/td><td>?<\/td><td>Control centre IT network offline for 12\u201324h after a ransomware attack<sup data-fn=\"9f82a816-3550-432b-9388-892af52195de\" class=\"fn\"><a href=\"#9f82a816-3550-432b-9388-892af52195de\" id=\"9f82a816-3550-432b-9388-892af52195de-link\">8<\/a><\/sup> <\/td><td>N<\/td><\/tr><tr><td>Norway<\/td><td>2019<\/td><td>?<\/td><td>Reported loss of $67\u201384m; operators resorted to manual controls<sup data-fn=\"8b6092c3-8f44-4f40-ab78-4b1ad7ac2e33\" class=\"fn\"><a href=\"#8b6092c3-8f44-4f40-ab78-4b1ad7ac2e33\" id=\"8b6092c3-8f44-4f40-ab78-4b1ad7ac2e33-link\">9<\/a><\/sup><\/td><td>N<\/td><\/tr><tr><td>Ukraine<\/td><td>2022<\/td><td>TA5<\/td><td>Attempted attack early in the Russia\u2013Ukraine war, thwarted by defenders<\/td><td>N<\/td><\/tr><tr><td>Germany<\/td><td>2022<\/td><td>TA5<\/td><td>Attack on Viasat modems in Ukraine led to operator&#8217;s loss of control and view of 5,800 wind turbines (11GW) in Germany<sup data-fn=\"f69f8722-3630-4de0-ba5c-04ab3720ce10\" class=\"fn\"><a href=\"#f69f8722-3630-4de0-ba5c-04ab3720ce10\" id=\"f69f8722-3630-4de0-ba5c-04ab3720ce10-link\">10<\/a><\/sup><\/td><td>N<\/td><\/tr><tr><td>Ukraine<\/td><td>2022<\/td><td>TA5<\/td><td>Attack on substation caused outage coinciding with missile attack<sup data-fn=\"3e84f01e-432b-4a00-91d3-977a7e043e29\" class=\"fn\"><a href=\"#3e84f01e-432b-4a00-91d3-977a7e043e29\" id=\"3e84f01e-432b-4a00-91d3-977a7e043e29-link\">11<\/a><\/sup><\/td><td>Y<\/td><\/tr><tr><td>Denmark<\/td><td>2023<\/td><td>TA4\/5<\/td><td>One operator lost visibility into assets in three remote locations; the incident had \u201cno material impact to energy operations\u201d<sup data-fn=\"0ffdf62b-4675-43eb-a266-a48d31b8d2d5\" class=\"fn\"><a href=\"#0ffdf62b-4675-43eb-a266-a48d31b8d2d5\" id=\"0ffdf62b-4675-43eb-a266-a48d31b8d2d5-link\">12<\/a><\/sup><\/td><td>N<\/td><\/tr><\/tbody><\/table><\/div><figcaption class=\"wp-element-caption\"><strong>Table 3:<\/strong> Selected past grid cyberattacks<\/figcaption><\/figure>\n\n\n\n<p class=\"wp-block-paragraph\">Cyber-induced blackouts have been both infrequent and modest in scale. The three blackouts in Ukraine following grid cyberattacks resulted in outages lasting a few hours for fewer than one million people.<sup data-fn=\"bd2ae996-4db3-4c4c-9076-6ccacafa0d76\" class=\"fn\"><a href=\"#bd2ae996-4db3-4c4c-9076-6ccacafa0d76\" id=\"bd2ae996-4db3-4c4c-9076-6ccacafa0d76-link\">13<\/a><\/sup> We estimate these blackouts caused roughly $5 million in economic damages altogether.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">In these cyberattacks, attackers compromised Ukrainian utility companies, gained access to OT environments, and opened circuit breakers at substations, stopping power from flowing through the substation and causing outages. In the 2015 attack, attackers also disrupted communications between utility control centers and substations, forcing utilities to send field crews to affected substations to manually re-close the breakers before power could be restored. These attacks did not cause widespread physical damage to grid equipment or cascading failures \u2014 their impacts were fairly localized.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">By contrast, the worst accidental blackouts have caused much greater impacts. For example, the 2003 Northeast Blackout in the U.S. is estimated to have cost roughly $12 billion in 2024 dollars, affected about 50 million people, and lasted up to two days. In economic-damage terms, this represents roughly four orders of magnitude greater impact than the 2015 Ukraine attack.<\/p>\n\n\n\n<figure class=\"wp-block-table\"><div class=\"table-wrapper\"><table class=\"has-fixed-layout\"><tbody><tr><td><strong>Blackout<\/strong><\/td><td><strong>Type<\/strong><\/td><td><strong>Duration (hours)<\/strong><\/td><td><strong>Scope (millions of customers)<\/strong><\/td><td><strong>Damages (2024 USD)<\/strong><\/td><\/tr><tr><td>2003 Northeast US<\/td><td>Accident<\/td><td>43<\/td><td>24<\/td><td>$12B<\/td><\/tr><tr><td>2003 Italy\/Switzerland<\/td><td>Accident<\/td><td>15<\/td><td>20<\/td><td>$2B<\/td><\/tr><tr><td>2015 Ukraine<\/td><td>Cyberattack<\/td><td>3.5<\/td><td>0.2<\/td><td>~$0.1\u201310M<\/td><\/tr><tr><td>2016 Ukraine<\/td><td>Cyberattack<\/td><td>1<\/td><td>0.3<\/td><td>&lt;$0.1M<\/td><\/tr><tr><td>2022 Ukraine<\/td><td>Cyberattack<\/td><td>unknown<\/td><td>unknown<\/td><td>unknown<\/td><\/tr><\/tbody><\/table><\/div><figcaption class=\"wp-element-caption\"><strong>Table 4:<\/strong> Historical accidental blackouts and grid cyberattacks<\/figcaption><\/figure>\n\n\n\n<p class=\"wp-block-paragraph\">Beyond the historical record, several scenario estimates suggest that deliberate U.S. blackouts could cause damages of $100 billion or more under certain assumptions (Table 5). These estimates vary substantially in their assumptions, and only Lloyd\u2019s scenario explicitly describes a cyberattack.<\/p>\n\n\n\n<figure class=\"wp-block-table\"><div class=\"table-wrapper\"><table class=\"has-fixed-layout\"><tbody><tr><td><strong>Source<\/strong><\/td><td><strong>Damages<\/strong><\/td><td><strong>Region<\/strong><\/td><td><strong>Type<\/strong><\/td><td><strong>Scenario details<\/strong><\/td><\/tr><tr><td rowspan=\"2\">Lloyd\u2019s Business Blackout (2015)<sup data-fn=\"66a01e80-54c0-4e3c-aef7-c1372217ace6\" class=\"fn\"><a href=\"#66a01e80-54c0-4e3c-aef7-c1372217ace6\" id=\"66a01e80-54c0-4e3c-aef7-c1372217ace6-link\">14<\/a><\/sup><\/td><td rowspan=\"2\">$80\u2013300B economic costs<sup data-fn=\"f281756b-d552-4fb6-b14c-58f75f0497db\" class=\"fn\"><a href=\"#f281756b-d552-4fb6-b14c-58f75f0497db\" id=\"f281756b-d552-4fb6-b14c-58f75f0497db-link\">15<\/a><\/sup><\/td><td rowspan=\"2\">Eastern US<\/td><td rowspan=\"2\">Cyberattack<\/td><td rowspan=\"2\">Cyberattack causes a blackout over Eastern US.<br>3 scenarios ranging in severity, with time to restore 90% of power ranging from 2\u20134 weeks (lost load 19\u201368 TWh).<\/td><\/tr><tr><\/tr><tr><td>UK Risk Register (2025)<sup data-fn=\"d9b30f36-ba09-4cf7-9e5a-ea690924e5d6\" class=\"fn\"><a href=\"#d9b30f36-ba09-4cf7-9e5a-ea690924e5d6\" id=\"d9b30f36-ba09-4cf7-9e5a-ea690924e5d6-link\">16<\/a><\/sup><\/td><td>\u00a310\u2013100B<\/td><td>UK<\/td><td>Accident or deliberate<\/td><td>A total failure of the national transmission system leading to nationwide loss of power\u2014full restoration could take up to 7 days.<br><span style=\"font-family: inherit; font-size: inherit; font-weight: inherit;\">Note that the UK economy is ~8x smaller than US<\/span><\/td><\/tr><tr><td>Rose et al. (2007)<sup data-fn=\"cede08ec-fd27-4c8c-a50c-7ba10a3fc7a7\" class=\"fn\"><a href=\"#cede08ec-fd27-4c8c-a50c-7ba10a3fc7a7\" id=\"cede08ec-fd27-4c8c-a50c-7ba10a3fc7a7-link\">17<\/a><\/sup><\/td><td>$2\u201315B<\/td><td>LA County<\/td><td>Kinetic attack<\/td><td>Kinetic terrorist attack causes two-week blackout.<br>Estimates losses using 3 different assumptions about level of resilience.<br>Assuming linear recovery, damages of ~$2\u201315B, i.e. 13\u201394% loss of regional economic output.<br>Note that LA County is ~1\/30 of the US economy.<sup data-fn=\"ee18421f-4411-4ed7-935d-cceee011f872\" class=\"fn\"><a href=\"#ee18421f-4411-4ed7-935d-cceee011f872\" id=\"ee18421f-4411-4ed7-935d-cceee011f872-link\">18<\/a><\/sup><\/td><\/tr><tr><td>National Academy of Sciences 2012<sup data-fn=\"9a27dac1-c494-4c5e-a051-df2b248fb4c9\" class=\"fn\"><a href=\"#9a27dac1-c494-4c5e-a051-df2b248fb4c9\" id=\"9a27dac1-c494-4c5e-a051-df2b248fb4c9-link\">19<\/a><\/sup><\/td><td>$100B<\/td><td>US (unspecified scope)<\/td><td>Attack (unspecified cyber\/kinetic)<\/td><td>\u201cA systematically designed and executed terrorist attack [against the grid] could cause disruptions considerably more widespread and of much longer duration than the largest power system disruptions experienced to date \u2026. could lead to costs of hundreds of billions of dollars\u2014that is, perhaps as much as a few percent of the U.S. GDP.\u201d<\/td><\/tr><\/tbody><\/table><\/div><figcaption class=\"wp-element-caption\"><strong>Table 5:<\/strong> Selected estimates for worst-case deliberate blackouts<\/figcaption><\/figure>\n\n\n\n<p class=\"wp-block-paragraph\">The most relevant prior OT cyberattacks have required substantial time, resources, and specialized expertise, often from state-level actors. Beyond the significant resource and time investments, prior OT cyberattacks have required a diverse range of capabilities, including long-term reconnaissance, knowledge of the target OT environments, tailored malware, realistic test environments, and stealth.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">These requirements make the role of AI difficult to assess. AI could plausibly assist with some components of a grid attack, such as reconnaissance, code generation, vulnerability discovery, and operator decision support. It is less clear how much AI would help with other important bottlenecks, such as obtaining access to segmented OT systems, understanding highly specific grid configurations, avoiding detection, and coordinating an operation over time.<\/p>\n\n\n\n<h2 id=\"methods\" class=\"wp-block-heading\">Methods<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">To develop the survey, we used an iterative process in which the research team drafted forecasting questions, a small sample of experts and superforecasters answered them, and the team revised the questions in light of how respondents interpreted them. We conducted two rounds of this process. Because forecasts can be highly sensitive to question wording and resolution criteria, we revised the questions to improve clarity and focus on the most important aspects of AI capability progress. We focused the survey on two possible pathways to large-scale harms from AI: data-damaging worm attacks and attacks against the U.S. electrical grid. These pathways are only a subset of the ways that AI could be used to perpetrate cyberattacks. In addition to the survey questions, we also provided participants with some background information, which can be viewed in <a href=\"https:\/\/forecastingresearch.org\/wp-content\/uploads\/pdf\/ai-cyber-risks-capabilities.pdf#page=49\" target=\"_blank\" rel=\"noreferrer noopener\">Appendix A<\/a>.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Because this was designed as a pilot study, we used convenience sampling and aimed for a sample of around 15 to 30 people.<sup data-fn=\"a4a6e06d-ce89-47bf-87a6-b60d7aad217b\" class=\"fn\"><a href=\"#a4a6e06d-ce89-47bf-87a6-b60d7aad217b\" id=\"a4a6e06d-ce89-47bf-87a6-b60d7aad217b-link\">20<\/a><\/sup> We invited two groups of respondents: 1. people with expertise in cybersecurity and AI impacts on cybersecurity (<em>\u201cexperts\u201d<\/em>) and 2. superforecasters, who are people who have previously scored highly in geopolitical forecasting tournaments. A total sample of 33 people was invited to participate via email. To incentivize engagement, we paid participants for the time they spent completing the survey; the average payment was $700. Participants responded to the main survey between July 23<sup>rd<\/sup> and August 29<sup>th<\/sup>, 2025.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">A few months after the main survey, we recontacted participants with a short, one-hour follow-up survey to capture any significant changes in their views. In this survey, we presented a summary of the main results from the original survey (aggregate numerical results and a description of the main arguments given by participants), as well as a description of Anthropic\u2019s cybersecurity incident report.<sup data-fn=\"6a60a24a-3095-4672-ac74-599107b16074\" class=\"fn\"><a href=\"#6a60a24a-3095-4672-ac74-599107b16074\" id=\"6a60a24a-3095-4672-ac74-599107b16074-link\">21<\/a><\/sup> Participants reflected on these and were given the opportunity to update a subset of their forecasts between December 11<sup>th<\/sup>, 2025 and January 6<sup>th<\/sup>, 2026. For more details, see <a href=\"https:\/\/forecastingresearch.org\/wp-content\/uploads\/pdf\/ai-cyber-risks-capabilities.pdf#page=56\" target=\"_blank\" rel=\"noreferrer noopener\">Appendix B<\/a>.<\/p>\n\n\n\n<h3 id=\"survey-structure\" class=\"wp-block-heading\">Survey structure<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">We asked participants to consider two cyberattack pathways. For the first scenario, in which a data-damaging worm attack causes at least $10 billion in economic damages in 2026, participants were asked to provide:<\/p>\n\n\n\n<ol class=\"wp-block-list\">\n<li>Baseline (unconditional) forecasts of this risk\n<ol class=\"wp-block-list\">\n<li>Including holistic forecasts and forecasts of actor capability and willingness<\/li>\n<\/ol>\n<\/li>\n\n\n\n<li>Forecasts conditional on the outcomes of a hypothetical AI capability scenario:\n<ol class=\"wp-block-list\">\n<li>Capability 1: Vulnerability and elite exploits uplift\n\n<ol class=\"wp-block-list\">\n<li>A study conducted at the end of 2025 finds that access to frontier AI models enables 25% of moderately-skilled individual hackers to find vulnerabilities and write elite exploits, assuming three months of full-time effort.<\/li>\n\n\n\n<li>P0: All models that meet Capability 1 are open-weight<\/li>\n<\/ol>\n<\/li>\n\n\n\n<li>Including holistic forecasts and forecasts of actor capability<\/li>\n<\/ol>\n<\/li>\n\n\n\n<li>Forecasts conditional on the implementation of two mitigation measures\n<ol class=\"wp-block-list\">\n<li>P1: Proprietary models with refusals and anti-jailbreak measures<\/li>\n\n\n\n<li>P2: Temporary protections with early access for defenders<\/li>\n<\/ol>\n<\/li>\n<\/ol>\n\n\n\n<p class=\"wp-block-paragraph\">For the second scenario, a cyberattack against the U.S. electrical grid causing a blackout with at least $10 billion (or at least $100 billion) in economic damages in 2026, participants provided:<\/p>\n\n\n\n<ol class=\"wp-block-list\">\n<li>Baseline (unconditional) forecasts of this risk\n<ol class=\"wp-block-list\">\n<li>Including holistic forecasts and forecasts of actor capability and willingness<\/li>\n\n\n\n<li>For both the $10 billion and $100 billion versions<\/li>\n<\/ol>\n<\/li>\n\n\n\n<li>Forecasts conditional on the outcomes of hypothetical scenarios:\n<ol class=\"wp-block-list\">\n<li>Capability 3: Uplift in an OT-specific capture-the-flag style competition\n\n<ol class=\"wp-block-list\">\n<li>A study is conducted at the end of 2025 to measure AI uplift on a CTF-style competition focused on industrial control systems (ICS) and OT cybersecurity, finds that, with access to AI, individual TA1 actors complete as high a proportion of tasks as a team of ten experienced cybersecurity professionals (equivalent to a TA3 actor) without access to AI, when both teams are given the same amount of time.<\/li>\n<\/ol>\n<\/li>\n\n\n\n<li>Capability 4: Real-world warning shot\n\n<ol class=\"wp-block-list\">\n<li>A cyberattack against the U.S. grid causes a blackout, leading to at least $100 million in economic damages, and is subsequently confirmed by credible sources to have been perpetrated by low- or moderately-skilled individual hackers using AI.<\/li>\n<\/ol>\n<\/li>\n<\/ol>\n<\/li>\n\n\n\n<li>Comments about relevant mitigation measures<\/li>\n<\/ol>\n\n\n\n<p class=\"wp-block-paragraph\">Questions around actor capability and willingness were intended to distinguish between an actor\u2019s capability to produce a specified outcome and their willingness to attempt such an attack, conditional on being capable. As such, financial damage values were present in the wording of both questions. It is possible that respondents had different interpretations of the capability questions, either as asking whether an actor could achieve the specific damage threshold, or more loosely as asking whether the actor could mount a serious attack of that general type. We discuss implications of this ambiguity where relevant as we present results.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">See <a href=\"https:\/\/forecastingresearch.org\/wp-content\/uploads\/pdf\/ai-cyber-risks-capabilities.pdf#page=44\" target=\"_blank\" rel=\"noreferrer noopener\">Appendix A<\/a> for the detailed survey questions and resolution criteria.<\/p>\n\n\n\n<h2 id=\"general-results\" class=\"wp-block-heading\">General results<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">The sample size for this study was small: 21 participants completed the original survey, including 13 superforecasters, six experts who completed the full survey, and two experts who completed shorter versions. We invited all respondents who completed the survey to participate in a follow-up study. Table 6 shows completion rates.<\/p>\n\n\n\n<figure class=\"wp-block-table\"><div class=\"table-wrapper\"><table class=\"has-fixed-layout\"><tbody><tr><td><\/td><td><strong>Total<\/strong><\/td><td><strong>Superforecasters<\/strong><\/td><td><strong>Experts<\/strong><\/td><\/tr><tr><td>Original survey<\/td><td>21<\/td><td>13<\/td><td>8<\/td><\/tr><tr><td>Follow-up survey<\/td><td>17<\/td><td>13<\/td><td>4<\/td><\/tr><tr><td><em>Proportion of original participants who completed the follow-up survey<\/em><\/td><td><em>81%<\/em><\/td><td><em>100%<\/em><\/td><td><em>50%<\/em><\/td><\/tr><\/tbody><\/table><\/div><figcaption class=\"wp-element-caption\"><strong>Table 6:<\/strong> Survey sample description.<\/figcaption><\/figure>\n\n\n\n<h3 id=\"threat-actors\" class=\"wp-block-heading\">Threat actors<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">Some forecasting questions referred to the TA1\u2013TA5 threat actor categories introduced earlier in the report. For estimating the number of actors in each category, we treated states as single, unitary threat actors. For instance, we treated China as a single threat actor, rather than treating each Chinese state or state-backed advanced persistent threat (APT) group as a separate actor.<sup data-fn=\"e642d9ba-731e-4cd2-b4bf-6c23df0357a3\" class=\"fn\"><a href=\"#e642d9ba-731e-4cd2-b4bf-6c23df0357a3\" id=\"e642d9ba-731e-4cd2-b4bf-6c23df0357a3-link\">22<\/a><\/sup><\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Figure 3 shows estimates of the number of threat actors in each category, and Table 7 breaks these estimates down by participant group.<\/p>\n\n\n\n<figure class=\"wp-block-table\"><div class=\"table-wrapper\"><table class=\"has-fixed-layout\"><tbody><tr><td><\/td><td><strong>TA1<\/strong><\/td><td><strong>TA2<\/strong><\/td><td><strong>TA3<\/strong><\/td><td><strong>TA4<\/strong><\/td><td><strong>TA5<\/strong><\/td><\/tr><tr><td>Experts<\/td><td>1.2m<br>(115k, 3.75m)<\/td><td>24k<br>(8.3k, 71k)<\/td><td>300<br>(169, 500)<\/td><td>13<br>(9, 18)<\/td><td>4<br>(4, 5)<\/td><\/tr><tr><td>Superforecasters<\/td><td>1m<br>(300k, 5.5m)<\/td><td>50k<br>(20k, 250k)<\/td><td>500<br>(300, 4.5k)<\/td><td>50<br>(20, 75)<\/td><td>6<br>(5, 10)<\/td><\/tr><\/tbody><\/table><\/div><figcaption class=\"wp-element-caption\"><strong>Table 7:<\/strong> Estimates of the number of threat actors in each TA category. Values are group medians, with interquartile ranges shown in parentheses.<\/figcaption><\/figure>\n\n\n\n<figure class=\"wp-block-image size-full\" id=\"fig-03\"><img decoding=\"async\" src=\"https:\/\/forecastingresearch.org\/wp-content\/uploads\/2026\/07\/paper_2026-07-07_ai-cyber-risks-capabilities_fig-03.png\" alt=\"\"\/><figcaption class=\"wp-element-caption\"><strong>Figure 3:<\/strong> Participant forecasts of the number of threat actors in each TA category. Labels show medians from the full sample.<\/figcaption><\/figure>\n\n\n\n<h2 id=\"data-damaging-worms-results\" class=\"wp-block-heading\">Data-damaging worms: results<\/h2>\n\n\n\n<h3 id=\"baseline-forecasts\" class=\"wp-block-heading\">Baseline forecasts<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">Participants first provided a baseline forecast for the probability that a data-damaging worm attack would cause at least $10 billion in economic damages in 2026. The median expert forecast was 8% (IQR: 5\u201310%), and the median superforecaster forecast was 5% (IQR: 2\u20138%). Figure 4 shows participants&#8217; responses to this question.<\/p>\n\n\n\n<figure class=\"wp-block-image size-full\" id=\"fig-04\"><img decoding=\"async\" src=\"https:\/\/forecastingresearch.org\/wp-content\/uploads\/2026\/07\/paper_2026-07-07_ai-cyber-risks-capabilities_fig-04.png\" alt=\"\"\/><figcaption class=\"wp-element-caption\"><strong>Figure 4:<\/strong> Forecasts of the probability of at least one data-damaging worm attack causing at least $10 billion in economic damages in 2026.<\/figcaption><\/figure>\n\n\n\n<p class=\"wp-block-paragraph\">Participants\u2019 rationales commonly referenced the very low base rate for events of this kind, noting that $10 billion would be a damage level with few precedents for this type of attack. Many noted that only TA4 and TA5 actors would have the resources to conduct this scale of attack. Although some participants noted that there are several active conflicts or areas of geopolitical tension globally (Ukraine\/Russia, Iran\/Israel, China\/Taiwan) they also noted that there is generally little motivation for major powers to use cyberattack capabilities. Some respondents suggested that AI could cause future outcomes to depart from historical patterns, but thought that 2026 would probably be too soon for this effect to dominate. There were mixed views on whether improved cyberdefense outweighs potential for greater harm in a more digitally dependent society.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Conditional on an event of this magnitude occurring in 2026, participants thought TA4 and TA5 actors were the most likely causes. For both experts and superforecasters, these actors accounted for roughly 80% of the probability (see Figure 5).<\/p>\n\n\n\n<figure class=\"wp-block-image size-full\" id=\"fig-05\"><img decoding=\"async\" src=\"https:\/\/forecastingresearch.org\/wp-content\/uploads\/2026\/07\/paper_2026-07-07_ai-cyber-risks-capabilities_fig-05.png\" alt=\"\"\/><figcaption class=\"wp-element-caption\"><strong>Figure 5:<\/strong> Average probability assigned to each threat actor type as the primary cause of a data-damaging worm attack, conditional on such an attack occurring in 2026 and causing at least $10 billion in damages.<\/figcaption><\/figure>\n\n\n\n<p class=\"wp-block-paragraph\">Rationales for this question noted that historical attacks of comparable magnitudes were attributed to TA4\/5 actors. TA4 actors were considered slightly more likely than TA5 actors because they were perceived as more motivated to conduct such an attack and less constrained by escalation concerns. Many participants noted that it seemed close to impossible for a TA1 or TA2 actor to succeed at such an attack. A TA3 actor would be unlikely but could perhaps succeed with state support or access to leaked exploits.<\/p>\n\n\n\n<h3 id=\"forecasts-conditional-on-ai-capabilities-and-mitigations\" class=\"wp-block-heading\">Forecasts conditional on AI capabilities and mitigations<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">We then asked participants how their forecast would change under a hypothetical AI-capability scenario. This scenario, labeled Capability 1, involved AI enabling moderately-skilled individual hackers (TA2 actors) to find vulnerabilities and write elite exploits. It was described as:<\/p>\n\n\n\n<div class=\"wp-block-group\"><div class=\"wp-block-group__inner-container is-layout-constrained wp-block-group-is-layout-constrained\">\n<h4 class=\"wp-block-heading\">BOX 1: CAPABILITY 1 DESCRIPTION<\/h4>\n\n\n\n<p class=\"wp-block-paragraph\">Capability 1: AI enables TA2 actors to write elite exploits.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">A study conducted at the end of 2025 finds that access to frontier AI models enables 25% of moderately-skilled individual hackers (TA2 actors) to find vulnerabilities and write elite exploits, assuming three months of full-time effort.<\/p>\n<\/div><\/div>\n\n\n\n<p class=\"wp-block-paragraph\">Participants then assumed that this capability had been achieved and that models with this capability were available open-weight without any cyber safeguards (mitigation scenario P0). Under these assumptions, the median expert forecast of the probability of a data-damaging worm attack causing at least $10 billion in 2026 rose to 41% (IQR: 17.5\u201378.8%). For the median superforecaster, it rose to 15% (IQR: 5\u201328%). (See Figure 6.) The median relative increase in risk was 3.5x (IQR: 2\u201310.8x) for experts and 3x (IQR: 2\u20136x) for superforecasters.<\/p>\n\n\n\n<figure class=\"wp-block-image size-full\" id=\"fig-06\"><img decoding=\"async\" src=\"https:\/\/forecastingresearch.org\/wp-content\/uploads\/2026\/07\/paper_2026-07-07_ai-cyber-risks-capabilities_fig-06.png\" alt=\"\"\/><figcaption class=\"wp-element-caption\"><strong>Figure 6:<\/strong> Forecasts of the probability of at least one data-damaging worm attack causing at least $10 billion in economic damages in 2026, conditional on Capability 1 (AI enables 25% of moderately-skilled individual hackers (TA2) to write elite exploits).<\/figcaption><\/figure>\n\n\n\n<p class=\"wp-block-paragraph\">There was general consensus that this scenario would represent a substantial increase in risk. Rationales noted that finding elite exploits would remove the most important bottleneck for TA2 actors, and given the large number of these actors and their lack of restraint compared to TA5 actors, this would indicate a substantial increase in risk. Actors newly enabled by this capability were also thought more likely to cause massive damage accidentally through poorly targeted attacks. Participants noted that this capability could also indicate an increase in the capabilities of higher level threat actors (TA3 to TA5). Finally, several participants emphasized a defense-offense timing imbalance: although AI helps both sides, there may be a \u201cdangerous window of vulnerability\u201d when new capabilities first emerge.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">We then asked participants to say how their forecasts would change conditional on mitigations being put in place (still assuming Capability 1 had been met). We asked about two mitigation scenarios, described below.<\/p>\n\n\n\n<div class=\"wp-block-group\"><div class=\"wp-block-group__inner-container is-layout-constrained wp-block-group-is-layout-constrained\">\n<h4 class=\"wp-block-heading\">BOX 2: POLICY 1 DESCRIPTION<\/h4>\n\n\n\n<p class=\"wp-block-paragraph\">P1: Proprietary models with refusals and anti-jailbreak measures<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li>The models used in the study (and similar models) are all proprietary and companies train the models to refuse to respond to requests for potentially harmful information. Open-weight models are no better than the best open-weight models as of August 31, 2024.<\/li>\n\n\n\n<li>Companies require users to access them via APIs that are subject to the following safeguards:<\/li>\n\n\n\n<li>Pre-deployment red-teaming to identify jailbreaks<\/li>\n\n\n\n<li>A voluntary goal of not letting any new universal jailbreak remain unpatched for more than 2-weeks over any given three-month period.<\/li>\n\n\n\n<li>A \u201cbug bounty\u201d program that offers up to $15,000 rewards for anyone who identifies and reports a universal jailbreak for one of their models.<\/li>\n\n\n\n<li>Information security practices at \u201cSecurity Level 2\u201d as described in the 2024 RAND report \u201cSecuring AI Model Weights: Preventing Theft and Misuse of Frontier Models\u201d (see pp. 25-6).<\/li>\n<\/ul>\n<\/div><\/div>\n\n\n\n<div class=\"wp-block-group\"><div class=\"wp-block-group__inner-container is-layout-constrained wp-block-group-is-layout-constrained\">\n<h4 class=\"wp-block-heading\">BOX 3: POLICY 2 DESCRIPTION<\/h4>\n\n\n\n<p class=\"wp-block-paragraph\">P2: Temporary protections with early access for defenders<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li>The public release of the model has P1 level safeguards in place. However, a specific set of \u2018cyber defenders\u2019 is given access to a version of the model without any P1 cyber protections, i.e. with full vulnerability discovery and exploit development capabilities.&nbsp;<\/li>\n\n\n\n<li>The set of cyber defenders includes only Microsoft, Meta, Apple, and Google and the world\u2019s best highly vetted bug bounty hunters.<\/li>\n\n\n\n<li>After four months, the model is released under P0 security, i.e., is open weight.<\/li>\n<\/ul>\n<\/div><\/div>\n\n\n\n<p class=\"wp-block-paragraph\">The detailed description of these scenarios, which was provided to participants, is available in <a href=\"https:\/\/forecastingresearch.org\/wp-content\/uploads\/pdf\/ai-cyber-risks-capabilities.pdf#page=50\" target=\"_blank\" rel=\"noreferrer noopener\">Appendix A<\/a>.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Both groups of participants generally thought that these measures would meaningfully reduce risk. The median expert believed that mitigation scenario P1 (proprietary models with refusals and anti-jailbreak measures) would more than halve the probability of a data-damaging worm causing at least $10 billion in damages, conditional on Capability 1 (Figure 7). Experts generally thought that P1 offered better protection than P2 (temporary protections with early access for defenders), with the median expert respondent believing that P2 offered half the risk reduction of P1. Conversely, the superforecaster participants generally thought that P2 offered a similar risk reduction to P1.<\/p>\n\n\n\n<figure class=\"wp-block-image size-full\" id=\"fig-07\"><img decoding=\"async\" src=\"https:\/\/forecastingresearch.org\/wp-content\/uploads\/2026\/07\/paper_2026-07-07_ai-cyber-risks-capabilities_fig-07.png\" alt=\"\"\/><figcaption class=\"wp-element-caption\"><strong>Figure 7:<\/strong> Relative risk of a \u2265$10 billion data-damaging worm conditional on Capability 1 and the two mitigation scenarios.<\/figcaption><\/figure>\n\n\n\n<p class=\"wp-block-paragraph\">Respondents generally thought P1 would have the greatest impact on TA1 and TA2 actors, because actors with higher operational capacity might bypass the protections. Some respondents noted that being able to quickly patch vulnerabilities matters more than working against specific jailbreaks. API-based access was thought to help with identifying suspicious patterns, but it was noted that it would still be hard to differentiate malicious actors from legitimate researchers. Many participants were concerned that sophisticated actors could steal model weights, remove safeguards, and offer elite exploits as a service. They noted that API-based access would not fully address this risk. Some respondents thought that red-teaming requirements can sometimes be \u201csafety-washing\u201d and suggested this protection would likely be inefficient. Some respondents noted that jailbreak measures provide limited protection.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">In rationales for forecasts relating to P2, participants often suggested that four months might be an insufficient head start for defenders, as defenders must guard a large attack surface and there may be many vulnerabilities to patch, making prioritization difficult. Some respondents argued that the eventual open-weight release would reduce the value of early defender access because attackers would still be able to use the models over the long term.<\/p>\n\n\n\n<h3 id=\"actor-capability-to-conduct-large-scale-worm-cyberattacks\" class=\"wp-block-heading\">Actor capability to conduct large-scale worm cyberattacks<sup data-fn=\"1f389b32-940f-474a-85bd-812670e23986\" class=\"fn\"><a href=\"#1f389b32-940f-474a-85bd-812670e23986\" id=\"1f389b32-940f-474a-85bd-812670e23986-link\">23<\/a><\/sup><\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">We asked participants how capability and willingness to launch a data-damaging worm attack causing at least $10 billion in damages vary across threat actor categories. Both groups of participants generally thought that TA1 to TA3 actors were very unlikely to be able to develop a data-damaging worm and that almost all TA5 actors would have this capability (see Figure 8). Opinions were more mixed about the capabilities of TA4 actors, with the median expert suggesting that a randomly selected TA4 actor has just a 5% (IQR: 1\u201325%) probability of being able to create a data-damaging worm, and the median superforecaster putting the probability at 40% (IQR: 25\u201353%).<\/p>\n\n\n\n<figure class=\"wp-block-image size-full\" id=\"fig-08\"><img decoding=\"async\" src=\"https:\/\/forecastingresearch.org\/wp-content\/uploads\/2026\/07\/paper_2026-07-07_ai-cyber-risks-capabilities_fig-08.png\" alt=\"\"\/><figcaption class=\"wp-element-caption\"><strong>Figure 8:<\/strong> Probability that a randomly selected actor in each threat actor class is able to develop a data-damaging worm given 3 months of effort.<\/figcaption><\/figure>\n\n\n\n<p class=\"wp-block-paragraph\">Finding elite exploits was seen as the most difficult part of developing this type of worm attack. Although the median expert thought that a randomly selected TA3 actor would have a 1% (IQR: 1\u20135%) chance of finding elite exploits, they would have a 16.5% (IQR: 2.1\u201352.5%) chance of performing the other steps necessary to develop a large-scale data-damaging worm. (See <a href=\"https:\/\/forecastingresearch.org\/wp-content\/uploads\/pdf\/ai-cyber-risks-capabilities.pdf#page=66\" target=\"_blank\" rel=\"noreferrer noopener\">Appendix C<\/a> for more detail.)<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">When asked to condition on Capability 1 (access to frontier AI models enables 25% of TA2 actors to find vulnerabilities and write elite exploits), participants, particularly experts, increased their estimate of the probability that a randomly selected actor could develop a data-damaging worm. In this hypothetical scenario, the median expert put a 51.5% (IQR: 14.5\u201386.3%) probability of a TA3 actor succeeding at this task, and a 13.8% (IQR: 3.5\u201320.8%) probability of a TA2 actor succeeding (Figure 9). Participants noted that damage at this scale requires rapid development and coordination, so organized groups were still favored over individuals even with the emerging AI capabilities.<\/p>\n\n\n\n<figure class=\"wp-block-image size-full\" id=\"fig-09\"><img decoding=\"async\" src=\"https:\/\/forecastingresearch.org\/wp-content\/uploads\/2026\/07\/paper_2026-07-07_ai-cyber-risks-capabilities_fig-09.png\" alt=\"\"\/><figcaption class=\"wp-element-caption\"><strong>Figure 9:<\/strong> Probability that a randomly selected actor in each threat actor class is able to develop a data-damaging worm with 3 months of effort, conditional on access to frontier AI models enabling 25% of TA2 actors to find vulnerabilities and write elite exploits.<\/figcaption><\/figure>\n\n\n\n<h3 id=\"actor-willingness-to-engage-in-large-scale-worm-cyberattacks\" class=\"wp-block-heading\">Actor willingness to engage in large-scale worm cyberattacks<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">We asked participants to estimate the probability that at least one actor in a class would be willing to launch a data-damaging worm attack if they were capable of doing so. Both groups gave high estimates\u2013greater than 95%\u2013for TA1 and TA2 actors, suggesting that the large number of such actors makes it almost certain that at least one would be willing to conduct such an attack. Some respondents noted that there is a roughly inverse relationship between willingness and capability, as more capable actors are constrained by serious geopolitical consequences.<\/p>\n\n\n\n<figure class=\"wp-block-image size-full\" id=\"fig-10\"><img decoding=\"async\" src=\"https:\/\/forecastingresearch.org\/wp-content\/uploads\/2026\/07\/paper_2026-07-07_ai-cyber-risks-capabilities_fig-10.png\" alt=\"\"\/><figcaption class=\"wp-element-caption\"><strong>Figure 10:<\/strong> Probability that at least one actor in each threat actor class would spend 3 or more months actively attempting to launch a data-damaging worm in 2026, assuming the actor had the capability to do so.<\/figcaption><\/figure>\n\n\n\n<h3 id=\"expected-damages\" class=\"wp-block-heading\">Expected damages<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">We asked participants to forecast the probability that data-damaging worms would cause different ranges of total economic damages in 2026. The median expert assigned a 20% probability to damages between $100 million and $1 billion (IQR: 8\u201335%), but a 0.095% probability to damages between $1 trillion and $10 trillion (IQR: 0.01\u20130.1%). Experts and superforecasters broadly had similar estimates across the magnitude scale (see Figure 11), but differed in their estimates of the mid-range bin ($10 billion\u2013$100 billion) (p = 0.04).<\/p>\n\n\n\n<figure class=\"wp-block-image size-full\" id=\"fig-11\"><img decoding=\"async\" src=\"https:\/\/forecastingresearch.org\/wp-content\/uploads\/2026\/07\/paper_2026-07-07_ai-cyber-risks-capabilities_fig-11.png\" alt=\"\"\/><figcaption class=\"wp-element-caption\"><strong>Figure 11:<\/strong> Forecasted probability that data-damaging worm attacks cause total economic damages in each range in 2026.<\/figcaption><\/figure>\n\n\n\n<p class=\"wp-block-paragraph\">We used these binned probabilities to calculate expected damages. Participants could revise the calculated value if they felt like it did not capture their beliefs about expected damages from data-damaging worms in 2026. A few participants modified the values, but the aggregate results, especially for experts, remained consistent (see Figure 12).<\/p>\n\n\n\n<figure class=\"wp-block-image size-full\" id=\"fig-12\"><img decoding=\"async\" src=\"https:\/\/forecastingresearch.org\/wp-content\/uploads\/2026\/07\/paper_2026-07-07_ai-cyber-risks-capabilities_fig-12.png\" alt=\"\"\/><figcaption class=\"wp-element-caption\"><strong>Figure 12:<\/strong> Calculated and participant-confirmed expected damages from data-damaging worm attacks in 2026.<\/figcaption><\/figure>\n\n\n\n<p class=\"wp-block-paragraph\">We then asked how these probabilities would change conditional on AI reaching Capability 1. Figure 13 shows these forecasts, and Figure 14 shows both the calculated expected damages and participants\u2019 adjusted expected damages estimates under this condition. As before, both groups had similar estimates across the bins, with a significant difference only for the mid-range bin ($10 billion\u2013$100 billion), in which the median expert placed significantly more weight (p = 0.04).<\/p>\n\n\n\n<figure class=\"wp-block-image size-full\" id=\"fig-13\"><img decoding=\"async\" src=\"https:\/\/forecastingresearch.org\/wp-content\/uploads\/2026\/07\/paper_2026-07-07_ai-cyber-risks-capabilities_fig-13.png\" alt=\"\"\/><figcaption class=\"wp-element-caption\"><strong>Figure 13:<\/strong> Forecasted probability that data-damaging worm attacks cause total economic damages in each range in 2026, conditional on Capability 1 (AI enables 25% of TA2 actors to write elite exploits).<\/figcaption><\/figure>\n\n\n\n<p class=\"wp-block-paragraph\">Using the participants\u2019 confirmed expected damages estimates, Capability 1 is associated with a 3\u20135x increase in expected damages, from approximately $15 billion to $67 billion for the median expert forecast and from $10 billion to $33 billion for the median superforecaster forecast. Overall, experts expected a much higher increase in damages conditional on AI reaching Capability 1.<\/p>\n\n\n\n<figure class=\"wp-block-image size-full\" id=\"fig-14\"><img decoding=\"async\" src=\"https:\/\/forecastingresearch.org\/wp-content\/uploads\/2026\/07\/paper_2026-07-07_ai-cyber-risks-capabilities_fig-14.png\" alt=\"\"\/><figcaption class=\"wp-element-caption\"><strong>Figure 14:<\/strong> Calculated and participant-confirmed expected damages from data-damaging worms in 2026, conditional on Capability 1 (AI enables TA2 actors to write elite exploits).<\/figcaption><\/figure>\n\n\n\n<h3 id=\"forecast-updates\" class=\"wp-block-heading\">Forecast updates<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">After reviewing a summary of the original survey\u2019s numerical results and key arguments, participants were given the opportunity to revise their forecasts of the main outcome: the probability that a data-damaging worm attack would cause at least $10 billion in economic damages in 2026. Forecasts generally shifted toward the crowd consensus. However, experts were less likely to update than superforecasters; only one of the four experts who completed the follow-up survey revised their estimate. As a result, aggregate median forecasts remained unchanged, while the interquartile range narrowed for superforecasters (Figure 15). The expert median differs slightly here (7% versus 8% in Figure 4) because only a subset of experts participated in the follow-up survey.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">When asked to reflect on how the results and arguments impacted their updates, participants expressed a mix of agreement with the results and disagreement on some key assumptions. Superforecasters questioned how large of a capability boost experts attributed to the scenario where Capability 1 had been met, citing that there would be additional real-world operational and defensive constraints. Other disagreements concerned the historical base rate of worm attacks, the willingness of higher-sophistication actors (TA3\u2013TA5), and the strength of deterrents such as law enforcement, escalation risks, and cyber defenses.<\/p>\n\n\n\n<figure class=\"wp-block-image size-full\" id=\"fig-15\"><img decoding=\"async\" src=\"https:\/\/forecastingresearch.org\/wp-content\/uploads\/2026\/07\/paper_2026-07-07_ai-cyber-risks-capabilities_fig-15.png\" alt=\"\"\/><figcaption class=\"wp-element-caption\"><strong>Figure 15:<\/strong> Updated forecasts from the follow-up survey of the probability of at least one data-damaging worm attack causing at least $10 billion in economic damages in 2026. Only responses from participants who completed both the original and follow-up surveys are shown.<\/figcaption><\/figure>\n\n\n\n<p class=\"wp-block-paragraph\">Participants were presented with a summary of Anthropic\u2019s report describing an AI-assisted cyber espionage campaign using Claude,<sup data-fn=\"9a13a3ce-e43f-4456-95ad-80c993fe60e5\" class=\"fn\"><a href=\"#9a13a3ce-e43f-4456-95ad-80c993fe60e5\" id=\"9a13a3ce-e43f-4456-95ad-80c993fe60e5-link\">24<\/a><\/sup> and were asked whether this information changed their forecasts. Overall, the report was seen as evidence of rapidly advancing AI-cyber capabilities, particularly as it showed AI can automate large portions of multi-stage attacks. Most participants said this was broadly consistent with their prior expectations of AI progress in this area and did not lead to major updates, while a minority questioned the credibility of key claims in the report.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Participants highlighted that the implications of the report were mostly relevant for TA3 and some TA4 actors, as the campaign showed a level of automation that suggested lower resource and coordination barriers than previously assumed. However, participants believed the attack still relied on known vulnerabilities, while advanced capabilities\u2013such as discovering zero-day vulnerabilities or developing elite exploits\u2013remain key bottlenecks for less sophisticated actors. Participants also stressed that the report centers around industrial espionage rather than a worm attack, limiting its direct relevance to the main outcome in question. As a result, although the report reinforced expectations of near-term rapid AI progress in cybersecurity, most participants did not think it substantially increased the likelihood of a large-scale data-damaging worm attack by 2026.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Participants identified the numerical results from the original study, the Anthropic cyber espionage report, and the study\u2019s rationales as the primary drivers of forecast updates (see Figure 16). The numerical results were the largest contributor, and drove updates in both directions as participants moved toward the crowd consensus. The Anthropic report and general AI progress consistently pushed participants to raise their forecasts of the main outcome, while policy developments had a more mixed effect, leading some participants to increase and others to decrease their risk estimates.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Qualitatively, upward revisions were typically driven by evidence of faster than anticipated AI progress, particularly as outlined in the Anthropic report, as well as increased concern about the willingness of state actors and the potential for geopolitical escalation. Downward revisions emphasized the role of defensive improvements alongside offensive capabilities.<\/p>\n\n\n\n<figure class=\"wp-block-image size-full\" id=\"fig-16\"><img decoding=\"async\" src=\"https:\/\/forecastingresearch.org\/wp-content\/uploads\/2026\/07\/paper_2026-07-07_ai-cyber-risks-capabilities_fig-16.png\" alt=\"\"\/><figcaption class=\"wp-element-caption\"><strong>Figure 16:<\/strong> Impact of each information source on participants\u2019 forecast updates.<\/figcaption><\/figure>\n\n\n\n<h2 id=\"electrical-grid-cyberattacks-results\" class=\"wp-block-heading\">Electrical grid cyberattacks: results<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">In addition to the data-damaging worm scenario, we asked participants to consider a 2026 cyberattack against the U.S. electrical grid that causes a blackout with at least $10 billion or at least $100 billion in economic damages.<\/p>\n\n\n\n<h3 id=\"baseline-forecasts-1\" class=\"wp-block-heading\">Baseline forecasts<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">Participants generally gave very low forecasts for these events. The median expert and superforecaster both forecast a 1% chance of a grid cyberattack causing at least $10 billion in damages (IQR: 0.48\u20131.5% for experts and IQR: 0.5\u20132% for superforecasters) and a 0.1% chance of an attack causing at least $100 billion in damages (IQR: 0.002\u20130.15% for experts and IQR: 0.05\u20130.12% for superforecasters). Figure 17 shows participants&#8217; responses to this question.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">When justifying their forecasts, participants often pointed to the lack of historical precedent, noting that even major past incidents caused significantly less damage. They noted that kinetic attacks could be more effective than cyberattacks at damaging the grid, and that cyber-induced damage may be easier to repair than physical damage. It was generally thought that geopolitical conflict would be a key driver of this risk, as attacks of this level would require sophisticated state-level actors with significant operational and technology expertise. Such an attack was seen as more likely to be an act of war than criminal activity, with some participants citing the potential for U.S.-China conflict.<\/p>\n\n\n\n<figure class=\"wp-block-image size-full\" id=\"fig-17\"><img decoding=\"async\" src=\"https:\/\/forecastingresearch.org\/wp-content\/uploads\/2026\/07\/paper_2026-07-07_ai-cyber-risks-capabilities_fig-17.png\" alt=\"\"\/><figcaption class=\"wp-element-caption\"><strong>Figure 17:<\/strong> Forecasts of the probability of at least one cyberattack against the U.S. electrical grid causing at least $10 billion or at least $100 billion in economic damages in 2026.<\/figcaption><\/figure>\n\n\n\n<p class=\"wp-block-paragraph\">Experts thought that, were such an event to occur, TA5 actors would be the most likely cause: conditional on a grid cyberattack causing at least $10 billion in damages, the average expert assigned a 73% probability to TA5 actors being the cause (IQR: 62\u201392%). Superforecasters also thought TA5 actors were the most likely cause (average probability of 40%, with IQR 22\u201350%), although, compared to experts, they placed substantially more weight on other actors, particularly TA4 (35%, IQR: 28\u201340%) (see Figure 18). Results were similar for an attack causing \u2265$100 billion in damages (see <a href=\"https:\/\/forecastingresearch.org\/wp-content\/uploads\/pdf\/ai-cyber-risks-capabilities.pdf#page=66\" target=\"_blank\" rel=\"noreferrer noopener\">Appendix C<\/a>).<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Generally, respondents thought that this capability would only be available to more sophisticated actors. Some also suggested that less capable actors would have little interest in this type of attack, preferring financially-motivated crimes instead. The constraints on more sophisticated actors (e.g., avoiding retaliation) were again mentioned, however, some respondents suggested that states might operate through proxies to allow plausible deniability. Rationales often mentioned China, with many referring to Volt Typhoon, a Chinese state-sponsored threat actor reportedly responsible for widespread intrusions into critical-infrastructure networks.<sup data-fn=\"269d9bc5-94ea-4ddc-8d4a-240dc488fa9c\" class=\"fn\"><a href=\"#269d9bc5-94ea-4ddc-8d4a-240dc488fa9c\" id=\"269d9bc5-94ea-4ddc-8d4a-240dc488fa9c-link\">25<\/a><\/sup><\/p>\n\n\n\n<figure class=\"wp-block-image size-full\" id=\"fig-18\"><img decoding=\"async\" src=\"https:\/\/forecastingresearch.org\/wp-content\/uploads\/2026\/07\/paper_2026-07-07_ai-cyber-risks-capabilities_fig-18.png\" alt=\"\"\/><figcaption class=\"wp-element-caption\"><strong>Figure 18:<\/strong> Average probability assigned to each threat actor type as the primary cause of a cyberattack against the U.S. grid, conditional on such an attack causing at least $10 billion in damages in 2026.<\/figcaption><\/figure>\n\n\n\n<h3 id=\"forecasts-conditional-on-ai-capabilities\" class=\"wp-block-heading\">Forecasts conditional on AI capabilities<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">We next asked participants how their forecast would change under hypothetical scenarios involving open-weight frontier AI models and AI capabilities. These AI capability scenarios were defined as:<\/p>\n\n\n\n<div class=\"wp-block-group\"><div class=\"wp-block-group__inner-container is-layout-constrained wp-block-group-is-layout-constrained\">\n<h4 class=\"wp-block-heading\">BOX 4: CAPABILITY 3 DESCRIPTION<\/h4>\n\n\n\n<p class=\"wp-block-paragraph\">Capability 3: AI enables TA1 actors to perform like a TA3 actor in an OT-specific capture-the-flag style competition.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">A study conducted at the end of 2025 to measure AI uplift on a CTF-style competition focused on industrial control systems (ICS) and OT cybersecurity, finds that, with access to AI, individual TA1 actors complete as high a proportion of tasks as a team of ten experienced cybersecurity professionals (equivalent to a TA3 actor) without access to AI, when both teams are given the same amount of time.<\/p>\n<\/div><\/div>\n\n\n\n<div class=\"wp-block-group\"><div class=\"wp-block-group__inner-container is-layout-constrained wp-block-group-is-layout-constrained\">\n<h4 class=\"wp-block-heading\">BOX 5: CAPABILITY 4 DESCRIPTION<\/h4>\n\n\n\n<p class=\"wp-block-paragraph\">Capability 4: Real-world incident: warning shot.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">A cyberattack on the U.S. grid causes a blackout, leading to \u2265$100 million in economic damages, and is subsequently confirmed by credible sources to have been perpetrated by a TA1- or TA2-level actor using AI.<\/p>\n<\/div><\/div>\n\n\n\n<p class=\"wp-block-paragraph\">Both experts and superforecasters thought Capability 3 would have only a small impact on the risk of a grid cyberattack causing at least $10 billion in damages in the U.S. in 2026. Under this scenario, the median forecast of this outcome rose to 1.5% (IQR: 1\u20137%) (from a baseline of 1%) for experts and 2% (IQR: 1\u201310%) for superforecasters. Under Capability 4, the median expert forecast of a grid cyberattack causing at least $10 billion in damages in 2026 rose to 15% (IQR: 2\u201320%). For the median superforecaster, it rose to 4% (IQR: 2.1\u20138%). (Figure 19.) Figure 20 shows how forecasts of \u2265$100 billion changed conditional on these capabilities.<\/p>\n\n\n\n<figure class=\"wp-block-image size-full\" id=\"fig-19\"><img decoding=\"async\" src=\"https:\/\/forecastingresearch.org\/wp-content\/uploads\/2026\/07\/paper_2026-07-07_ai-cyber-risks-capabilities_fig-19.png\" alt=\"\"\/><figcaption class=\"wp-element-caption\"><strong>Figure 19:<\/strong> Forecasts of the probability of at least one cyberattack against the U.S. electrical grid causing at least $10 billion in economic damages in 2026, under baseline assumptions, and conditional on Capability 3 (AI enables TA1 actors to perform like a TA3 actor in an OT-specific capture-the-flag style competition) and Capability 4 (a real-world warning shot incident).<\/figcaption><\/figure>\n\n\n\n<figure class=\"wp-block-image size-full\" id=\"fig-20\"><img decoding=\"async\" src=\"https:\/\/forecastingresearch.org\/wp-content\/uploads\/2026\/07\/paper_2026-07-07_ai-cyber-risks-capabilities_fig-20.png\" alt=\"\"\/><figcaption class=\"wp-element-caption\"><strong>Figure 20:<\/strong> Forecasts of the probability of at least one cyberattack against the U.S. electrical grid causing at least $100 billion in economic damages in 2026, under baseline assumptions, and conditional on Capability 3 (AI enables TA1 actors to perform like a TA3 actor in an OT-specific capture-the-flag style competition) and Capability 4 (a real-world warning shot incident).<\/figcaption><\/figure>\n\n\n\n<p class=\"wp-block-paragraph\">When explaining their forecasts for Capability 3, respondents noted limitations of CTF competitions, especially that they often do not simulate actively defended networks or real operational complexity. Some also shared the opinion that conducting a grid attack is a multifaceted operation, requiring not only technical cyber skills, but also reconnaissance, operational coordination, physical access, and more. Some respondents suggested that this task would be beyond the capabilities of a TA3 actor, so uplifting TA1 actors to this level would have limited impact on this risk. Some respondents noted that the number of attempts may increase, but it\u2019s very likely they would be unsuccessful, although one respondent highlighted the danger of less experienced actors attempting attacks without fully understanding the potential downsides of their actions. Some respondents also suggested that an increase in risk would drive investment in grid security, making the task even more difficult.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Respondents who indicated that Capability 4 would suggest an increase in risk argued that a successful $100 million attack would show that AI had lowered technical barriers and could attract copycat attempts. However, many participants also suggested that a warning shot would trigger a significant increase in defenses. Some noted a tension between the \u201cwake-up call\u201d effect, which could strengthen defenses, and the window of vulnerability before those defenses improved. Some participants voiced uncertainty about whether conducting an attack that causes $10 billion in damage (rather than $100 million) is a qualitatively different challenge.<\/p>\n\n\n\n<h3 id=\"actor-capability-and-willingness-to-launch-large-scale-grid-attacks\" class=\"wp-block-heading\">Actor capability and willingness to launch large-scale grid attacks<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">As in the data-damaging worm scenario, we asked participants how capability and willingness to launch a grid cyberattack causing at least $10 billion in damages vary across threat actor categories. Both groups of participants generally thought it was close to impossible for a TA1 or TA2 actor to succeed at this task with six months of effort, with median forecasts of 0% probability that a randomly selected actor has the capabilities to launch such an attack. For the other actor types, superforecasters generally put a higher probability on their chances of success. For example, the median superforecaster estimated a 65% probability of a TA5 actor having the capability (IQR: 40\u201390%), compared to the median expert forecast of 25% (IQR: 6\u201342.5%) (Figure 21). Rationales suggested that many participants thought the U.S. and China may have this capability, but that this is difficult to assess given the lack of precedent.<\/p>\n\n\n\n<figure class=\"wp-block-image size-full\" id=\"fig-21\"><img decoding=\"async\" src=\"https:\/\/forecastingresearch.org\/wp-content\/uploads\/2026\/07\/paper_2026-07-07_ai-cyber-risks-capabilities_fig-21.png\" alt=\"\"\/><figcaption class=\"wp-element-caption\"><strong>Figure 21:<\/strong> Probability that a randomly selected actor in each threat actor class is able to launch a cyberattack against the U.S. grid with 6 months of effort, causing at least $10 billion in economic damages.<\/figcaption><\/figure>\n\n\n\n<p class=\"wp-block-paragraph\">Comparing these results with the $100 billion version in <a href=\"https:\/\/forecastingresearch.org\/wp-content\/uploads\/pdf\/ai-cyber-risks-capabilities.pdf#page=69\" target=\"_blank\" rel=\"noreferrer noopener\">Appendix C<\/a> suggests they should be interpreted with caution. Notably, for TA5 actors, the median expert capability estimate falls from 25% to 2%, while the median superforecaster estimate changes much less, from 65% to 58%. This may mean superforecasters saw little additional capability required to scale from $10 billion to a $100 billion attack. Alternatively, they may have read capability more loosely as the ability to mount a serious attack aimed at the damage threshold proposed, without separately accounting for whether the attack would actually achieve the specified damage. Experts may have tied capability more strongly to directly achieving the threshold through the attack. Some of the divergence between the two groups in these forecasts may be attributable to this ambiguity in the wording of the question.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">In general, respondents thought that all types of threat actors would be less willing to conduct a large-scale grid attack than a large-scale worm attack (Figure 22). Some respondents noted that there is a roughly inverse relationship between willingness and capability, as more capable actors are constrained by serious geopolitical consequences. Rationales emphasized that a grid attack would not fit the financial motivations that drive most less sophisticated actors, and that TA5 actors would be constrained by retaliation concerns, limiting such attacks largely to acts of war.<\/p>\n\n\n\n<figure class=\"wp-block-image size-full\" id=\"fig-22\"><img decoding=\"async\" src=\"https:\/\/forecastingresearch.org\/wp-content\/uploads\/2026\/07\/paper_2026-07-07_ai-cyber-risks-capabilities_fig-22.png\" alt=\"\"\/><figcaption class=\"wp-element-caption\"><strong>Figure 22:<\/strong> Probability that at least one actor in each threat actor class would spend 6 or more months actively attempting to launch a cyberattack against the U.S. electrical grid, causing a blackout with at least $10 billion in economic damages in 2026, assuming the actor had the capability to do so.<\/figcaption><\/figure>\n\n\n\n<h3 id=\"expected-damages-1\" class=\"wp-block-heading\">Expected damages<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">As with worm attacks, we asked participants to forecast the probability that cyberattacks against the U.S. electrical grid would cause different ranges of total economic damages in 2026. The median expert forecasted a 3% probability of such damages falling between $100 million and $1 billion (IQR: 1.3\u201315%), and a 0.0032% probability of such damages falling between $1 trillion and $10 trillion (IQR: 0.0001\u20130.006%) (Figure 23). Superforecaster medians were close to an order of magnitude larger: 10% (IQR: 2\u201316%) and 0.02% (IQR: 0.0001\u20130.1%), respectively.<\/p>\n\n\n\n<figure class=\"wp-block-image size-full\" id=\"fig-23\"><img decoding=\"async\" src=\"https:\/\/forecastingresearch.org\/wp-content\/uploads\/2026\/07\/paper_2026-07-07_ai-cyber-risks-capabilities_fig-23.png\" alt=\"\"\/><figcaption class=\"wp-element-caption\"><strong>Figure 23:<\/strong> Forecasted probability that cyberattacks on the U.S. grid cause total economic damages in each range in 2026.<\/figcaption><\/figure>\n\n\n\n<p class=\"wp-block-paragraph\">We used these binned probabilities to calculate an expected damages value and participants could revise the calculated value if they felt like it did not capture their beliefs. These values (shown in Figure 24) were more than an order of magnitude smaller than for data-damaging worm attacks. Participants noted that the largest-scale attacks seemed extremely unlikely, while one participant observed that even very small tail probabilities can skew the calculated expected damages very high.<\/p>\n\n\n\n<figure class=\"wp-block-image size-full\" id=\"fig-24\"><img decoding=\"async\" src=\"https:\/\/forecastingresearch.org\/wp-content\/uploads\/2026\/07\/paper_2026-07-07_ai-cyber-risks-capabilities_fig-24.png\" alt=\"\"\/><figcaption class=\"wp-element-caption\"><strong>Figure 24:<\/strong> Calculated and participant-confirmed expected damages from cyberattacks against the U.S. electrical grid in 2026.<\/figcaption><\/figure>\n\n\n\n<p class=\"wp-block-paragraph\">We also asked how these forecasts would change conditional on the following AI capability:<\/p>\n\n\n\n<div class=\"wp-block-group\"><div class=\"wp-block-group__inner-container is-layout-constrained wp-block-group-is-layout-constrained\">\n<h4 class=\"wp-block-heading\">BOX 6: CAPABILITY 2 DESCRIPTION<\/h4>\n\n\n\n<p class=\"wp-block-paragraph\">Capability 2: AI solves more than 90% of Cybench tasks<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">AI alone can solve more than 90% of the tasks on Cybench, completely unguided, at the end of 2025.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><em>Cybench is an industry-standard benchmark of AI capabilities across six cybersecurity categories: cryptography, web security, reverse engineering, forensics, exploitation, and miscellaneous.<\/em><sup data-fn=\"2b581d30-63bf-4aec-99dd-864364f766b6\" class=\"fn\"><a href=\"#2b581d30-63bf-4aec-99dd-864364f766b6\" id=\"2b581d30-63bf-4aec-99dd-864364f766b6-link\">26<\/a><\/sup><em> It includes 40 capture-the-flag (CTF) tasks of varying difficulties, drawn from real-world CTF competitions such as HackTheBox and Glacier. Cybench was designed to evolve over time and to incorporate new tasks that remain relevant as capabilities progress.<\/em><\/p>\n<\/div><\/div>\n\n\n\n<p class=\"wp-block-paragraph\">Conditioning on this capability led to a roughly 4x increase in expected damages for the median expert and a roughly doubling of expected damages for the median superforecaster (Figure 25 and Figure 26). Rationales suggested that some participants expected such capabilities to be associated with many more attempts by many actors leading to more small-scale attacks, which could add up to slightly higher total damages, though not significantly larger. Some participants noted that capabilities are not the limiting factor \u2014 deterrence, escalation risks and human coordination are still bigger constraints, and this capability would not help with those. Some also argued that once an AI-enabled attack succeeded, defenders\u2013especially the U.S. government\u2013would rapidly harden defenses.<\/p>\n\n\n\n<figure class=\"wp-block-image size-full\" id=\"fig-25\"><img decoding=\"async\" src=\"https:\/\/forecastingresearch.org\/wp-content\/uploads\/2026\/07\/paper_2026-07-07_ai-cyber-risks-capabilities_fig-25.png\" alt=\"\"\/><figcaption class=\"wp-element-caption\"><strong>Figure 25:<\/strong> Forecasted probability that cyberattacks against the U.S. grid cause total economic damages in each range in 2026, conditional on Capability 2 (AI solves at least 90% of Cybench tasks).<\/figcaption><\/figure>\n\n\n\n<figure class=\"wp-block-image size-full\" id=\"fig-26\"><img decoding=\"async\" src=\"https:\/\/forecastingresearch.org\/wp-content\/uploads\/2026\/07\/paper_2026-07-07_ai-cyber-risks-capabilities_fig-26.png\" alt=\"\"\/><figcaption class=\"wp-element-caption\"><strong>Figure 26:<\/strong> Calculated and participant-confirmed expected damages from cyberattacks against the U.S. electrical grid in 2026, conditional on Capability 2 (AI solves at least 90% of Cybench tasks).<\/figcaption><\/figure>\n\n\n\n<h3 id=\"comments-on-mitigations\" class=\"wp-block-heading\">Comments on mitigations<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">We asked participants to note any thoughts or comments on mitigations they considered relevant to this threat model: a large-scale cyberattack against the U.S. electrical grid. Their responses centered on two broad categories: grid and institutional resilience, and AI-specific defenses.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">On the grid infrastructure side, several participants emphasized the importance of physically separating critical control systems from internet-connected networks, increasing redundancy and decentralization to reduce the risk of cascading failures, maintaining manual overrides and backup systems, and stockpiling spare equipment to support faster recovery after an attack. Participants also flagged the need for stronger vetting of personnel with access to critical systems.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Participants also identified several AI-specific mitigations. Some suggested that highly capable AI systems could be made available earlier or differentially to defenders, similar to the early-access scenario considered for the data-damaging worm scenario. Others emphasized the importance of using AI-powered tools for anomaly detection, attack detection, and other defensive capabilities. Additional suggestions included monitoring model queries, conducting mandatory red-teaming focused on industrial-control-system protocols such as Modbus, DNP3, and relevant IEC standards, strengthening vetting and logging for API access to advanced models, and imposing strict restrictions on highly capable open-weight models.<\/p>\n\n\n\n<h2 id=\"forecasts-of-ai-progress-on-relevant-capabilities\" class=\"wp-block-heading\">Forecasts of AI progress on relevant capabilities<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">We asked participants to forecast when each of the following capabilities would be met:<\/p>\n\n\n\n<ol class=\"wp-block-list\">\n<li><strong>Capability 1: AI enables TA2 actors to write elite exploits<\/strong>\n\n<ol class=\"wp-block-list\">\n<li>A study finds that access to frontier AI models enables 25% of moderately-skilled individual hackers to find vulnerabilities and write elite exploits, assuming three months of full-time effort.<\/li>\n<\/ol>\n<\/li>\n\n\n\n<li><strong>Capability 2: AI solves at least 90% of Cybench tasks<\/strong>\n\n<ol class=\"wp-block-list\">\n<li>AI alone can solve at least 90% of the tasks on Cybench completely unguided.<\/li>\n<\/ol>\n<\/li>\n\n\n\n<li><strong>Capability 3: AI enables TA1 actors to perform like a TA3 actor in an OT-specific capture-the-flag style competition<\/strong>\n\n<ol class=\"wp-block-list\">\n<li>A study is conducted to measure AI uplift on a CTF-style competition focused on industrial control systems (ICS) and OT cybersecurity, finds that, with access to AI, individual TA1 actors complete as high a proportion of tasks as a team of ten experienced cybersecurity professionals (equivalent to a TA3 actor) without access to AI, when both teams are given the same amount of time.<\/li>\n<\/ol>\n<\/li>\n\n\n\n<li><strong>Capability 4: Real-world incident: warning shot<\/strong>\n\n<ol class=\"wp-block-list\">\n<li>A cyberattack against the U.S. grid causes a blackout with at least $100 million in economic damages and is subsequently confirmed by credible sources to have been perpetrated by a TA1- or TA2-level actor using AI.<\/li>\n<\/ol>\n<\/li>\n<\/ol>\n\n\n\n<p class=\"wp-block-paragraph\">Respondents generally expected these capabilities to be achieved within about six years (Figure 27). The median expert forecast placed Capability 1 in 2032, Capability 2 and Capability 3 in 2028, and Capability 4 in 2031. Since the survey closed in August 2025, Capability 2 appears to have been achieved. Recent evaluations also suggest rapid progress on Capability 1, though it remains unclear whether current frontier models meet the capability as defined here.<sup data-fn=\"adf6bfc5-9713-4cd2-9528-dc97f3186e69\" class=\"fn\"><a href=\"#adf6bfc5-9713-4cd2-9528-dc97f3186e69\" id=\"adf6bfc5-9713-4cd2-9528-dc97f3186e69-link\">27<\/a><\/sup><\/p>\n\n\n\n<figure class=\"wp-block-image size-full\" id=\"fig-27\"><img loading=\"lazy\" decoding=\"async\" width=\"2031\" height=\"1081\" src=\"https:\/\/forecastingresearch.org\/wp-content\/uploads\/2026\/07\/paper_2026-07-07_ai-cyber-risks-capabilities_fig-27.png\" alt=\"\" class=\"wp-image-2476\" srcset=\"https:\/\/forecastingresearch.org\/wp-content\/uploads\/2026\/07\/paper_2026-07-07_ai-cyber-risks-capabilities_fig-27.png 2031w, https:\/\/forecastingresearch.org\/wp-content\/uploads\/2026\/07\/paper_2026-07-07_ai-cyber-risks-capabilities_fig-27-350x186.png 350w, https:\/\/forecastingresearch.org\/wp-content\/uploads\/2026\/07\/paper_2026-07-07_ai-cyber-risks-capabilities_fig-27-700x373.png 700w, https:\/\/forecastingresearch.org\/wp-content\/uploads\/2026\/07\/paper_2026-07-07_ai-cyber-risks-capabilities_fig-27-768x409.png 768w, https:\/\/forecastingresearch.org\/wp-content\/uploads\/2026\/07\/paper_2026-07-07_ai-cyber-risks-capabilities_fig-27-1536x818.png 1536w, https:\/\/forecastingresearch.org\/wp-content\/uploads\/2026\/07\/paper_2026-07-07_ai-cyber-risks-capabilities_fig-27-2000x1065.png 2000w, https:\/\/forecastingresearch.org\/wp-content\/uploads\/2026\/07\/paper_2026-07-07_ai-cyber-risks-capabilities_fig-27-1200x639.png 1200w, https:\/\/forecastingresearch.org\/wp-content\/uploads\/2026\/07\/paper_2026-07-07_ai-cyber-risks-capabilities_fig-27-150x80.png 150w\" sizes=\"auto, (max-width: 2031px) 100vw, 2031px\" \/><figcaption class=\"wp-element-caption\"><strong>Figure 27:<\/strong> Forecasts of the year in which participants expected each AI capability to be achieved.<\/figcaption><\/figure>\n\n\n\n<p class=\"wp-block-paragraph\">To understand the signal provided by Cybench, we asked participants to forecast the probability that Capability 1 (AI enables 25% of TA2 actors to write elite exploits) and Capability 3 (AI enables TA1 actors to perform like a TA3 actor in an OT-specific CTF) would be achieved, conditional on Capability 2 (AI solves at least 90% of Cybench tasks) being achieved. Generally, experts thought Cybench provided greater signal of other capabilities, compared to superforecasters (see Figure 28).<\/p>\n\n\n\n<figure class=\"wp-block-image size-full\" id=\"fig-28\"><img decoding=\"async\" src=\"https:\/\/forecastingresearch.org\/wp-content\/uploads\/2026\/07\/paper_2026-07-07_ai-cyber-risks-capabilities_fig-28.png\" alt=\"\"\/><figcaption class=\"wp-element-caption\"><strong>Figure 28:<\/strong> Forecasts of the probability that Capability 1 (AI enables TA2 actors to write elite exploits) and Capability 3 (AI enables TA1 actors to perform like a TA3 actor in an OT-specific CTF) will be achieved, conditional on Capability 2 (AI solves at least 90% of Cybench tasks) being achieved.<\/figcaption><\/figure>\n\n\n\n<h2 id=\"limitations\" class=\"wp-block-heading\">Limitations<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">This pilot study has important limitations that should be kept in mind when interpreting the results. Our sample included only 13 superforecasters and eight experts, two of whom completed only a subset of the questions. This makes the results sensitive to individual forecasts and the reported aggregate statistics fragile. Similarly, our convenience sample of experts may be biased toward people concerned about AI impacts on cybersecurity, and should not be treated as representative of cybersecurity experts as a whole. In addition, some expert participants had prior exposure to early drafts of related reports by our GovAI collaborators. This may have anchored their views or created shared framings and assumptions before the forecasting exercise.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">The questions in this study differed from typical forecasting exercises because they focused on hypothetical AI evaluations and low-probability, extreme societal events without clear resolvability. Many were conditional questions, meaning forecasters would not be scored on the accuracy of their predictions. This absence of performance incentives or feedback, combined with the unusual nature of some questions and the limited historical data available for certain scenarios, may affect the accuracy and usefulness of the forecasts.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">The follow-up survey introduces additional limitations: only a subset of the original participants completed it. In the follow-up, respondents were intentionally exposed to summary statistics, arguments, and external information so that we could understand how these inputs affected their views. This may have anchored updates or induced convergence towards the original consensus rather than encouraged independent reassessment.<\/p>\n\n\n\n<h2 id=\"conclusion\" class=\"wp-block-heading\">Conclusion<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">The study results suggest that AI capabilities could significantly increase some cyber risks in the near term. Both experts and superforecasters predicted substantial increases in the likelihood of a large-scale data-damaging worm attack when AI enables moderate-sophistication individual hackers to develop elite exploits. Median forecasts suggest that AI-enabled vulnerability discovery could increase the risk of large-scale worm attacks by 3\u20133.5x, with expected annual damages rising from roughly $10\u201315 billion to $33\u201367 billion. Respondents believed these capabilities could arrive within the next five to six years.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">At the same time, structured mitigation measures appear to matter. Participants believed that maintaining proprietary model access with strong anti-jailbreak and monitoring controls could more than halve the probability of such catastrophic outcomes. Limited early access for defenders was viewed as less effective, although still potentially useful.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Given the small sample size and the speculative nature of some scenarios, these results should be interpreted as directional rather than definitive. Nonetheless, they illustrate the value of structured forecasting for anticipating technology-driven security risks. Future work could explore a wider range of possible cyber harms and include a larger, more representative sample of relevant subject-matter experts.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\">Notes<\/h2>\n\n\n<ol class=\"wp-block-footnotes\"><li id=\"58fc9118-26c1-4962-abb0-631b2d38f0fe\">Anthropic. \u201cDisrupting the First Reported AI-Orchestrated Cyber Espionage Campaign.\u201d 2025. <a href=\"https:\/\/www.anthropic.com\/news\/disrupting-AI-espionage\">https:\/\/www.anthropic.com\/news\/disrupting-AI-espionage<\/a> Accessed: 2026-05-27. <a href=\"#58fc9118-26c1-4962-abb0-631b2d38f0fe-link\" aria-label=\"Jump to footnote reference 1\">\u21a9\ufe0e<\/a><\/li><li id=\"f890f4e9-8073-489c-9d19-5240c47094e0\">Crosignani, Matteo, Marco Macchiavelli, and Andr\u00e9 F. Silva. \u201cPirates without Borders: The Propagation of Cyberattacks through Firms\u2019 Supply Chains.\u201d 2023. <a href=\"https:\/\/doi.org\/10.1016\/j.jfineco.2022.12.002\">https:\/\/doi.org\/10.1016\/j.jfineco.2022.12.002<\/a> Journal of Financial Economics 147, no. 2: 432-448; Johansmeyer, Tom. 2024. \u201cPerception Shapes Reality: How Views on Financial Market Correlation Affect Capital Availability for Cyber Insurance.\u201d 2024. <a href=\"https:\/\/kar.kent.ac.uk\/106432\/\">https:\/\/kar.kent.ac.uk\/106432\/<\/a> Journal of Risk Management and Insurance 28, no. 1: 1-25. <a href=\"#f890f4e9-8073-489c-9d19-5240c47094e0-link\" aria-label=\"Jump to footnote reference 2\">\u21a9\ufe0e<\/a><\/li><li id=\"8487a169-7812-45cb-b769-6d626cec49cd\">Johansmeyer, Tom. 2024. \u201cPerception Shapes Reality: How Views on Financial Market Correlation Affect Capital Availability for Cyber Insurance.\u201d 2024. <a href=\"https:\/\/kar.kent.ac.uk\/106432\/\">https:\/\/kar.kent.ac.uk\/106432\/<\/a> Journal of Risk Management and Insurance 28, no. 1: 1-25. <a href=\"#8487a169-7812-45cb-b769-6d626cec49cd-link\" aria-label=\"Jump to footnote reference 3\">\u21a9\ufe0e<\/a><\/li><li id=\"94e3079e-6b1a-45c2-b494-b8abeaf8a3b2\">Nevo, Sella, Dan Lahav, Ajay Karpur, Yogev Bar-On, Henry Alexander Bradley, and Jeff Alstott. \u201cSecuring AI Model Weights: Preventing Theft and Misuse of Frontier Models\u201d. <a href=\"https:\/\/www.rand.org\/pubs\/research_reports\/RRA2849-1.html\">RAND Corporation<\/a>, 2024, pp. 9\u201310. DOI: 10.7249\/RRA2849-1. <a href=\"#94e3079e-6b1a-45c2-b494-b8abeaf8a3b2-link\" aria-label=\"Jump to footnote reference 4\">\u21a9\ufe0e<\/a><\/li><li id=\"7d6f06f0-962a-456f-a032-fb65d7b4b753\">Garton, David. \u201cPurdue Model Framework for Industrial Control Systems &amp; Cybersecurity Segmentation.\u201d 2019.\u00a0 Topic Paper 4-14, prepared for the National Petroleum Council Study on Oil and Natural Gas Transportation Infrastructure. <a href=\"#7d6f06f0-962a-456f-a032-fb65d7b4b753-link\" aria-label=\"Jump to footnote reference 5\">\u21a9\ufe0e<\/a><\/li><li id=\"4bad6543-932d-43e8-979a-cdfdecc05ff5\">US Department of Energy. \u201cDOE-417 Electric Emergency Incident and Disturbance Report\u201d <a href=\"https:\/\/doe417.pnnl.gov\/\">https:\/\/doe417.pnnl.gov\/<\/a> Accessed: 2026-05-27. <a href=\"#4bad6543-932d-43e8-979a-cdfdecc05ff5-link\" aria-label=\"Jump to footnote reference 6\">\u21a9\ufe0e<\/a><\/li><li id=\"277dd50e-c636-465c-b1e8-45d4864d89fa\">Alrich, Tom. 2019. \u201cIt\u2019s Official: The Event Reported in March Was a Real Cyber Attack.\u201d <a href=\"https:\/\/tomalrichblog.blogspot.com\/2019\/09\/its-official-event-reported-in-march.html\">Tom Alrich\u2019s Blog<\/a>, 2019. Accessed: 2026-05-27; North American Electric Reliability Corporation. \u201cRisks Posed by Firewall Firmware Vulnerabilities.\u201d <a href=\"https:\/\/www.nerc.com\/globalassets\/programs\/event-analysis\/lessons-learned\/20190901_risks_posed_by_firewall_firmware_vulnerabilities.pdf\">Lesson Learned<\/a>, 2019. <a href=\"#277dd50e-c636-465c-b1e8-45d4864d89fa-link\" aria-label=\"Jump to footnote reference 7\">\u21a9\ufe0e<\/a><\/li><li id=\"9f82a816-3550-432b-9388-892af52195de\">Alrich, Tom. \u201cWhen Will a Ransomware Attack Impact the Bulk Electric System? 2018.\u201d <a href=\"https:\/\/tomalrichblog.blogspot.com\/2020\/10\/when-will-ransomware-attack-impact-bulk.html\">Tom Alrich\u2019s Blog<\/a>, 2020. <a href=\"#9f82a816-3550-432b-9388-892af52195de-link\" aria-label=\"Jump to footnote reference 8\">\u21a9\ufe0e<\/a><\/li><li id=\"8b6092c3-8f44-4f40-ab78-4b1ad7ac2e33\">MITRE. \u201cCyber Risk to Mission Case Study\u201d 2022. <a href=\"https:\/\/apps.dtic.mil\/sti\/trecms\/pdf\/AD1183007.pdf\">https:\/\/apps.dtic.mil\/sti\/trecms\/pdf\/AD1183007.pdf<\/a> Accessed: 2026-05-27. <a href=\"#8b6092c3-8f44-4f40-ab78-4b1ad7ac2e33-link\" aria-label=\"Jump to footnote reference 9\">\u21a9\ufe0e<\/a><\/li><li id=\"f69f8722-3630-4de0-ba5c-04ab3720ce10\">Willuhn, Marian. \u201cSatellite Cyber Attack Paralyzes 11GW of German Wind Turbines.\u201d <a href=\"https:\/\/www.pv-magazine.com\/2022\/03\/01\/satellite-cyber-attack-paralyzes-11gw-of-german-wind-turbines\/\">pv magazine<\/a> 2022. <a href=\"#f69f8722-3630-4de0-ba5c-04ab3720ce10-link\" aria-label=\"Jump to footnote reference 10\">\u21a9\ufe0e<\/a><\/li><li id=\"3e84f01e-432b-4a00-91d3-977a7e043e29\">Proska, Ken, John Wolfram, Jared Wilson, Dan Black, Keith Lunden, Daniel Kapellmann Zafra, Nathan Brubaker, Tyler McLellan, and Chris Sistrunk. \u201cSandworm Disrupts Power in Ukraine Using a Novel Attack Against Operational Technology.\u201d <a href=\"https:\/\/cloud.google.com\/blog\/topics\/threat-intelligence\/sandworm-disrupts-power-ukraine-operational-technology\/\">Google Cloud Blog<\/a>, 2023. <a href=\"#3e84f01e-432b-4a00-91d3-977a7e043e29-link\" aria-label=\"Jump to footnote reference 11\">\u21a9\ufe0e<\/a><\/li><li id=\"0ffdf62b-4675-43eb-a266-a48d31b8d2d5\">Culler, Megan Jordan, Megan Mincemoyer Egan, Remy Vanece Stolworthy, and Jake P. Gentle. 2024. \u201cAttack Surface of Renewable Energy Technologies.\u201d 2024. INL\/CON-24-76414-Revision-0. <a href=\"https:\/\/inldigitallibrary.inl.gov\/content\/uploads\/50\/2026\/04\/Sort_90576.pdf#page=15\">Idaho National Laboratory<\/a> (p. 15); SektorCERT. \u201cThe Attack against Danish Critical Infrastructure.\u201d 2023 <a href=\"https:\/\/sektorcert.dk\/wp-content\/uploads\/2023\/11\/SektorCERT-The-attack-against-Danish-critical-infrastructure-TLP-CLEAR.pdf\">https:\/\/sektorcert.dk\/wp-content\/uploads\/2023\/11\/SektorCERT-The-attack-against-Danish-critical-infrastructure-TLP-CLEAR.pdf<\/a> <a href=\"#0ffdf62b-4675-43eb-a266-a48d31b8d2d5-link\" aria-label=\"Jump to footnote reference 12\">\u21a9\ufe0e<\/a><\/li><li id=\"bd2ae996-4db3-4c4c-9076-6ccacafa0d76\">Note that customers\u2260people. In the US, there are ~2.1 people per electricity customer. In Ukraine, the ratio is ~2.3 people per customer \u201417.7m electricity customers with a population of 41.2m. <br>Sources: U.S. Energy Information Administration. 2025. \u201cTable 1.2. Summary Statistics for the United States, 2014-2024.\u201d In <a href=\"https:\/\/www.eia.gov\/electricity\/annual\/table.php?t=epa_01_02.html\">Electric Power Annual<\/a>: With Data for 2024. Release date October 16, 2025; Energy Charter Secretariat. 2023. Ukrainian Energy Sector Evaluation and Damage Assessment, <a href=\"https:\/\/www.energycharter.org\/fileadmin\/DocumentsMedia\/Occasional\/2023_04_27_UA_sectoral_evaluation_and_damage_assessment_Version_IX.pdf#page=12\">Version IX<\/a>, April 27, 2023, p. 12. <a href=\"#bd2ae996-4db3-4c4c-9076-6ccacafa0d76-link\" aria-label=\"Jump to footnote reference 13\">\u21a9\ufe0e<\/a><\/li><li id=\"66a01e80-54c0-4e3c-aef7-c1372217ace6\">Lloyd\u2019s. \u201cThe Insurance Implications of a Cyber Attack on the U.S. Power Grid.\u201d London: Lloyd\u2019s, <a href=\"https:\/\/www.lloyds.com\/insights\/risk-reports\/business-blackout\">Business Blackout<\/a> 2015. <a href=\"#66a01e80-54c0-4e3c-aef7-c1372217ace6-link\" aria-label=\"Jump to footnote reference 14\">\u21a9\ufe0e<\/a><\/li><li id=\"f281756b-d552-4fb6-b14c-58f75f0497db\">They also estimate a cumulative GDP impact of $240\u20131,000bn over five years. <a href=\"#f281756b-d552-4fb6-b14c-58f75f0497db-link\" aria-label=\"Jump to footnote reference 15\">\u21a9\ufe0e<\/a><\/li><li id=\"d9b30f36-ba09-4cf7-9e5a-ea690924e5d6\">HM Government. <a href=\"https:\/\/assets.publishing.service.gov.uk\/media\/67b5f85732b2aab18314bbe4\/National_Risk_Register_2025.pdf\">National Risk Register<\/a>: 2025 Edition. London: Cabinet Office. <a href=\"#d9b30f36-ba09-4cf7-9e5a-ea690924e5d6-link\" aria-label=\"Jump to footnote reference 16\">\u21a9\ufe0e<\/a><\/li><li id=\"cede08ec-fd27-4c8c-a50c-7ba10a3fc7a7\">Rose, Adam, Gbadebo Oladosu, and Shu-Yi Liao. \u201cBusiness Interruption Impacts of a Terrorist Attack on the Electric Power System of Los Angeles: Customer Resilience to a Total Blackout.\u201d 2007. <a href=\"https:\/\/ideas.repec.org\/a\/wly\/riskan\/v27y2007i3p513-531.html\">Risk Analysis 27<\/a>, no. 3: 513-531. DOI: 10.1111\/j.1539-6924.2007.00912.x. <a href=\"#cede08ec-fd27-4c8c-a50c-7ba10a3fc7a7-link\" aria-label=\"Jump to footnote reference 17\">\u21a9\ufe0e<\/a><\/li><li id=\"ee18421f-4411-4ed7-935d-cceee011f872\"><a href=\"https:\/\/fred.stlouisfed.org\/series\/REALGDPALL06037\">https:\/\/fred.stlouisfed.org\/series\/REALGDPALL06037<\/a>; <a href=\"https:\/\/fred.stlouisfed.org\/series\/GDPCA\">https:\/\/fred.stlouisfed.org\/series\/GDPCA<\/a> <a href=\"#ee18421f-4411-4ed7-935d-cceee011f872-link\" aria-label=\"Jump to footnote reference 18\">\u21a9\ufe0e<\/a><\/li><li id=\"9a27dac1-c494-4c5e-a051-df2b248fb4c9\">National Research Council. \u201cTerrorism and the Electric Power Delivery System.\u201d National Academies Press, 2012, p. 16. DOI: <a href=\"https:\/\/nap.nationalacademies.org\/read\/12050\/chapter\/3#16\">10.17226\/12050<\/a>. <a href=\"#9a27dac1-c494-4c5e-a051-df2b248fb4c9-link\" aria-label=\"Jump to footnote reference 19\">\u21a9\ufe0e<\/a><\/li><li id=\"a4a6e06d-ce89-47bf-87a6-b60d7aad217b\">In convenience sampling, participants are recruited on the basis of being available and relatively easy to access. <a href=\"#a4a6e06d-ce89-47bf-87a6-b60d7aad217b-link\" aria-label=\"Jump to footnote reference 20\">\u21a9\ufe0e<\/a><\/li><li id=\"6a60a24a-3095-4672-ac74-599107b16074\">Anthropic. \u201cDisrupting the First Reported AI-Orchestrated Cyber Espionage Campaign.\u201d 2025. <a href=\"https:\/\/www.anthropic.com\/news\/disrupting-AI-espionage\">https:\/\/www.anthropic.com\/news\/disrupting-AI-espionage<\/a> Accessed: 2026-05-27. <a href=\"#6a60a24a-3095-4672-ac74-599107b16074-link\" aria-label=\"Jump to footnote reference 21\">\u21a9\ufe0e<\/a><\/li><li id=\"e642d9ba-731e-4cd2-b4bf-6c23df0357a3\">In this respect, our definition is different from that commonly used in cyber threat modelling. <a href=\"#e642d9ba-731e-4cd2-b4bf-6c23df0357a3-link\" aria-label=\"Jump to footnote reference 22\">\u21a9\ufe0e<\/a><\/li><li id=\"1f389b32-940f-474a-85bd-812670e23986\">We asked again about capability and willingness in the follow-up survey. It was completed by a subset of participants, including only 4 experts from the original sample, and took place several months after the initial survey. Participants had access to additional information and were given the opportunity to update their views. In <a href=\"https:\/\/forecastingresearch.org\/wp-content\/uploads\/pdf\/ai-cyber-risks-capabilities.pdf#page=68\" target=\"_blank\" rel=\"noreferrer noopener\">Appendix C<\/a> we present results for similar capability questions, where we ask about a longer 12-month time horizon. <a href=\"#1f389b32-940f-474a-85bd-812670e23986-link\" aria-label=\"Jump to footnote reference 23\">\u21a9\ufe0e<\/a><\/li><li id=\"9a13a3ce-e43f-4456-95ad-80c993fe60e5\">Anthropic. \u201cDisrupting the First Reported AI-Orchestrated Cyber Espionage Campaign.\u201d 2025. <a href=\"https:\/\/www.anthropic.com\/news\/disrupting-AI-espionage\">https:\/\/www.anthropic.com\/news\/disrupting-AI-espionage<\/a> Accessed: 2026-05-27. <a href=\"#9a13a3ce-e43f-4456-95ad-80c993fe60e5-link\" aria-label=\"Jump to footnote reference 24\">\u21a9\ufe0e<\/a><\/li><li id=\"269d9bc5-94ea-4ddc-8d4a-240dc488fa9c\">National Cyber Security Centre (NCSC). &#8220;Defending Against China-Nexus Covert Networks of Compromised Devices.&#8221; 2025. <a href=\"https:\/\/www.ncsc.gov.uk\/news\/defending-against-china-nexus-covert-networks-of-compromised-devices\">https:\/\/www.ncsc.gov.uk\/news\/defending-against-china-nexus-covert-networks-of-compromised-devices<\/a>. Accessed: 2026-05-27. <a href=\"#269d9bc5-94ea-4ddc-8d4a-240dc488fa9c-link\" aria-label=\"Jump to footnote reference 25\">\u21a9\ufe0e<\/a><\/li><li id=\"2b581d30-63bf-4aec-99dd-864364f766b6\">Zhang, Andy K., Neil Perry, Riya Dulepet, Joey Ji, Celeste Menders, Justin Lin, Eliot Jones, et al. \u201cCybench: A Framework for Evaluating Cybersecurity Capabilities and Risks of Language Models.\u201d <a href=\"https:\/\/proceedings.iclr.cc\/paper_files\/paper\/2025\/hash\/3e9412a9c1d93810ef3ef7825115016b-Abstract-Conference.html\">International Conference on Learning Representations<\/a> 2025. <a href=\"#2b581d30-63bf-4aec-99dd-864364f766b6-link\" aria-label=\"Jump to footnote reference 26\">\u21a9\ufe0e<\/a><\/li><li id=\"adf6bfc5-9713-4cd2-9528-dc97f3186e69\">The 90% threshold was first crossed on the <a href=\"https:\/\/cybench.github.io\/\">public Cybench leaderboard<\/a> by Claude Opus 4.6, which was added at 93% unguided solved on a 37-problem subset on February 6, 2026. Later, Claude Mythos Preview reached 100% on a 35-problem subset (Anthropic. &#8220;Claude Mythos Preview System Card.&#8221; 2026. <a href=\"https:\/\/www-cdn.anthropic.com\/7624816413e9b4d2e3ba620c5a5e091b98b190a5\/Claude%20Mythos%20Preview%20System%20Card.pdf\">https:\/\/www-cdn.anthropic.com\/7624816413e9b4d2e3ba620c5a5e091b98b190a5\/Claude%20Mythos%20Preview%20System%20Card.pdf<\/a>, p. 49. Accessed: 2026-05-27.). Recent model evaluations, including Anthropic\u2019s Claude Mythos system card and OpenAI\u2019s GPT-5.3-Codex cybersecurity evaluation, suggest substantial progress towards AI-enabled exploit development capabilities, although whether the models fully satisfy our definition remains uncertain. <a href=\"#adf6bfc5-9713-4cd2-9528-dc97f3186e69-link\" aria-label=\"Jump to footnote reference 27\">\u21a9\ufe0e<\/a><\/li><\/ol>\n\n\n<div class=\"wp-block-buttons is-layout-flex wp-block-buttons-is-layout-flex\">\n<div class=\"wp-block-button\"><a class=\"btn orange\" href=\"https:\/\/forecastingresearch.org\/pdf\/ai-cyber-risks-capabilities.pdf\" target=\"_blank\" rel=\"noreferrer noopener\">References and the Appendix are provided in the full PDF report <svg width=\"7\" height=\"9\" viewBox=\"0 0 7 9\" fill=\"none\" xmlns=\"http:\/\/www.w3.org\/2000\/svg\">\n  <path d=\"M0.000156283 8.60806L4.22416 4.33606V4.24006L0.000156283 6.10352e-05H1.80816L6.06416 4.28806L1.80816 8.60806H0.000156283Z\" fill=\"#102B23\"\/>\n<\/svg>\n<svg width=\"8\" height=\"10\" viewBox=\"0 0 8 10\" fill=\"none\" xmlns=\"http:\/\/www.w3.org\/2000\/svg\">\n  <path d=\"M0.601719 8.85794L4.82572 4.58594V4.48994L0.601719 0.249939H2.40972L6.66572 4.53794L2.40972 8.85794H0.601719Z\" fill=\"#102B23\"\/>\n<\/svg><\/a><\/div>\n<\/div>\n\n\n\n<p class=\"wp-block-paragraph\"><\/p>\n","protected":false},"excerpt":{"rendered":"A pilot study investigating how AI capabilities may affect near-term cybersecurity risk, focusing on two high-impact cyberattack pathways: data-damaging worm attacks and cyberattacks against the U.S. electrical grid.","protected":false},"featured_media":2390,"template":"","meta":{"footnotes":"[{\"content\":\"Anthropic. \u201cDisrupting the First Reported AI-Orchestrated Cyber Espionage Campaign.\u201d 2025. <a href=\\\"https:\/\/www.anthropic.com\/news\/disrupting-AI-espionage\\\">https:\/\/www.anthropic.com\/news\/disrupting-AI-espionage<\/a> Accessed: 2026-05-27.\",\"id\":\"58fc9118-26c1-4962-abb0-631b2d38f0fe\"},{\"content\":\"Crosignani, Matteo, Marco Macchiavelli, and Andr\u00e9 F. Silva. \u201cPirates without Borders: The Propagation of Cyberattacks through Firms\u2019 Supply Chains.\u201d 2023. <a href=\\\"https:\/\/doi.org\/10.1016\/j.jfineco.2022.12.002\\\">https:\/\/doi.org\/10.1016\/j.jfineco.2022.12.002<\/a> Journal of Financial Economics 147, no. 2: 432-448; Johansmeyer, Tom. 2024. \u201cPerception Shapes Reality: How Views on Financial Market Correlation Affect Capital Availability for Cyber Insurance.\u201d 2024. <a href=\\\"https:\/\/kar.kent.ac.uk\/106432\/\\\">https:\/\/kar.kent.ac.uk\/106432\/<\/a> Journal of Risk Management and Insurance 28, no. 1: 1-25.\",\"id\":\"f890f4e9-8073-489c-9d19-5240c47094e0\"},{\"content\":\"Johansmeyer, Tom. 2024. \u201cPerception Shapes Reality: How Views on Financial Market Correlation Affect Capital Availability for Cyber Insurance.\u201d 2024. <a href=\\\"https:\/\/kar.kent.ac.uk\/106432\/\\\">https:\/\/kar.kent.ac.uk\/106432\/<\/a> Journal of Risk Management and Insurance 28, no. 1: 1-25.\",\"id\":\"8487a169-7812-45cb-b769-6d626cec49cd\"},{\"content\":\"Nevo, Sella, Dan Lahav, Ajay Karpur, Yogev Bar-On, Henry Alexander Bradley, and Jeff Alstott. \u201cSecuring AI Model Weights: Preventing Theft and Misuse of Frontier Models\u201d. <a href=\\\"https:\/\/www.rand.org\/pubs\/research_reports\/RRA2849-1.html\\\">RAND Corporation<\/a>, 2024, pp. 9\u201310. DOI: 10.7249\/RRA2849-1.\",\"id\":\"94e3079e-6b1a-45c2-b494-b8abeaf8a3b2\"},{\"content\":\"Garton, David. \u201cPurdue Model Framework for Industrial Control Systems &amp; Cybersecurity Segmentation.\u201d 2019.\u00a0 Topic Paper 4-14, prepared for the National Petroleum Council Study on Oil and Natural Gas Transportation Infrastructure.\",\"id\":\"7d6f06f0-962a-456f-a032-fb65d7b4b753\"},{\"content\":\"US Department of Energy. \u201cDOE-417 Electric Emergency Incident and Disturbance Report\u201d <a href=\\\"https:\/\/doe417.pnnl.gov\/\\\">https:\/\/doe417.pnnl.gov\/<\/a> Accessed: 2026-05-27.\",\"id\":\"4bad6543-932d-43e8-979a-cdfdecc05ff5\"},{\"content\":\"Alrich, Tom. 2019. \u201cIt\u2019s Official: The Event Reported in March Was a Real Cyber Attack.\u201d <a href=\\\"https:\/\/tomalrichblog.blogspot.com\/2019\/09\/its-official-event-reported-in-march.html\\\">Tom Alrich\u2019s Blog<\/a>, 2019. Accessed: 2026-05-27; North American Electric Reliability Corporation. \u201cRisks Posed by Firewall Firmware Vulnerabilities.\u201d <a href=\\\"https:\/\/www.nerc.com\/globalassets\/programs\/event-analysis\/lessons-learned\/20190901_risks_posed_by_firewall_firmware_vulnerabilities.pdf\\\">Lesson Learned<\/a>, 2019.\",\"id\":\"277dd50e-c636-465c-b1e8-45d4864d89fa\"},{\"content\":\"Alrich, Tom. \u201cWhen Will a Ransomware Attack Impact the Bulk Electric System? 2018.\u201d <a href=\\\"https:\/\/tomalrichblog.blogspot.com\/2020\/10\/when-will-ransomware-attack-impact-bulk.html\\\">Tom Alrich\u2019s Blog<\/a>, 2020.\",\"id\":\"9f82a816-3550-432b-9388-892af52195de\"},{\"content\":\"MITRE. \u201cCyber Risk to Mission Case Study\u201d 2022. <a href=\\\"https:\/\/apps.dtic.mil\/sti\/trecms\/pdf\/AD1183007.pdf\\\">https:\/\/apps.dtic.mil\/sti\/trecms\/pdf\/AD1183007.pdf<\/a> Accessed: 2026-05-27.\",\"id\":\"8b6092c3-8f44-4f40-ab78-4b1ad7ac2e33\"},{\"content\":\"Willuhn, Marian. \u201cSatellite Cyber Attack Paralyzes 11GW of German Wind Turbines.\u201d <a href=\\\"https:\/\/www.pv-magazine.com\/2022\/03\/01\/satellite-cyber-attack-paralyzes-11gw-of-german-wind-turbines\/\\\">pv magazine<\/a> 2022.\",\"id\":\"f69f8722-3630-4de0-ba5c-04ab3720ce10\"},{\"content\":\"Proska, Ken, John Wolfram, Jared Wilson, Dan Black, Keith Lunden, Daniel Kapellmann Zafra, Nathan Brubaker, Tyler McLellan, and Chris Sistrunk. \u201cSandworm Disrupts Power in Ukraine Using a Novel Attack Against Operational Technology.\u201d <a href=\\\"https:\/\/cloud.google.com\/blog\/topics\/threat-intelligence\/sandworm-disrupts-power-ukraine-operational-technology\/\\\">Google Cloud Blog<\/a>, 2023.\",\"id\":\"3e84f01e-432b-4a00-91d3-977a7e043e29\"},{\"content\":\"Culler, Megan Jordan, Megan Mincemoyer Egan, Remy Vanece Stolworthy, and Jake P. Gentle. 2024. \u201cAttack Surface of Renewable Energy Technologies.\u201d 2024. INL\/CON-24-76414-Revision-0. <a href=\\\"https:\/\/inldigitallibrary.inl.gov\/content\/uploads\/50\/2026\/04\/Sort_90576.pdf#page=15\\\">Idaho National Laboratory<\/a> (p. 15); SektorCERT. \u201cThe Attack against Danish Critical Infrastructure.\u201d 2023 <a href=\\\"https:\/\/sektorcert.dk\/wp-content\/uploads\/2023\/11\/SektorCERT-The-attack-against-Danish-critical-infrastructure-TLP-CLEAR.pdf\\\">https:\/\/sektorcert.dk\/wp-content\/uploads\/2023\/11\/SektorCERT-The-attack-against-Danish-critical-infrastructure-TLP-CLEAR.pdf<\/a>\",\"id\":\"0ffdf62b-4675-43eb-a266-a48d31b8d2d5\"},{\"content\":\"Note that customers\u2260people. In the US, there are ~2.1 people per electricity customer. In Ukraine, the ratio is ~2.3 people per customer \u201417.7m electricity customers with a population of 41.2m. <br>Sources: U.S. Energy Information Administration. 2025. \u201cTable 1.2. Summary Statistics for the United States, 2014-2024.\u201d In <a href=\\\"https:\/\/www.eia.gov\/electricity\/annual\/table.php?t=epa_01_02.html\\\">Electric Power Annual<\/a>: With Data for 2024. Release date October 16, 2025; Energy Charter Secretariat. 2023. Ukrainian Energy Sector Evaluation and Damage Assessment, <a href=\\\"https:\/\/www.energycharter.org\/fileadmin\/DocumentsMedia\/Occasional\/2023_04_27_UA_sectoral_evaluation_and_damage_assessment_Version_IX.pdf#page=12\\\">Version IX<\/a>, April 27, 2023, p. 12.\",\"id\":\"bd2ae996-4db3-4c4c-9076-6ccacafa0d76\"},{\"content\":\"Lloyd\u2019s. \u201cThe Insurance Implications of a Cyber Attack on the U.S. Power Grid.\u201d London: Lloyd\u2019s, <a href=\\\"https:\/\/www.lloyds.com\/insights\/risk-reports\/business-blackout\\\">Business Blackout<\/a> 2015.\",\"id\":\"66a01e80-54c0-4e3c-aef7-c1372217ace6\"},{\"content\":\"They also estimate a cumulative GDP impact of $240\u20131,000bn over five years.\",\"id\":\"f281756b-d552-4fb6-b14c-58f75f0497db\"},{\"content\":\"HM Government. <a href=\\\"https:\/\/assets.publishing.service.gov.uk\/media\/67b5f85732b2aab18314bbe4\/National_Risk_Register_2025.pdf\\\">National Risk Register<\/a>: 2025 Edition. London: Cabinet Office.\",\"id\":\"d9b30f36-ba09-4cf7-9e5a-ea690924e5d6\"},{\"content\":\"Rose, Adam, Gbadebo Oladosu, and Shu-Yi Liao. \u201cBusiness Interruption Impacts of a Terrorist Attack on the Electric Power System of Los Angeles: Customer Resilience to a Total Blackout.\u201d 2007. <a href=\\\"https:\/\/ideas.repec.org\/a\/wly\/riskan\/v27y2007i3p513-531.html\\\">Risk Analysis 27<\/a>, no. 3: 513-531. DOI: 10.1111\/j.1539-6924.2007.00912.x.\",\"id\":\"cede08ec-fd27-4c8c-a50c-7ba10a3fc7a7\"},{\"content\":\"<a href=\\\"https:\/\/fred.stlouisfed.org\/series\/REALGDPALL06037\\\">https:\/\/fred.stlouisfed.org\/series\/REALGDPALL06037<\/a>; <a href=\\\"https:\/\/fred.stlouisfed.org\/series\/GDPCA\\\">https:\/\/fred.stlouisfed.org\/series\/GDPCA<\/a>\",\"id\":\"ee18421f-4411-4ed7-935d-cceee011f872\"},{\"content\":\"National Research Council. \u201cTerrorism and the Electric Power Delivery System.\u201d National Academies Press, 2012, p. 16. DOI: <a href=\\\"https:\/\/nap.nationalacademies.org\/read\/12050\/chapter\/3#16\\\">10.17226\/12050<\/a>.\",\"id\":\"9a27dac1-c494-4c5e-a051-df2b248fb4c9\"},{\"content\":\"In convenience sampling, participants are recruited on the basis of being available and relatively easy to access.\",\"id\":\"a4a6e06d-ce89-47bf-87a6-b60d7aad217b\"},{\"content\":\"Anthropic. \u201cDisrupting the First Reported AI-Orchestrated Cyber Espionage Campaign.\u201d 2025. <a href=\\\"https:\/\/www.anthropic.com\/news\/disrupting-AI-espionage\\\">https:\/\/www.anthropic.com\/news\/disrupting-AI-espionage<\/a> Accessed: 2026-05-27.\",\"id\":\"6a60a24a-3095-4672-ac74-599107b16074\"},{\"content\":\"In this respect, our definition is different from that commonly used in cyber threat modelling.\",\"id\":\"e642d9ba-731e-4cd2-b4bf-6c23df0357a3\"},{\"content\":\"We asked again about capability and willingness in the follow-up survey. It was completed by a subset of participants, including only 4 experts from the original sample, and took place several months after the initial survey. Participants had access to additional information and were given the opportunity to update their views. In <a href=\\\"https:\/\/forecastingresearch.org\/wp-content\/uploads\/pdf\/ai-cyber-risks-capabilities.pdf#page=68\\\" target=\\\"_blank\\\" rel=\\\"noreferrer noopener\\\">Appendix C<\/a> we present results for similar capability questions, where we ask about a longer 12-month time horizon.\",\"id\":\"1f389b32-940f-474a-85bd-812670e23986\"},{\"content\":\"Anthropic. \u201cDisrupting the First Reported AI-Orchestrated Cyber Espionage Campaign.\u201d 2025. <a href=\\\"https:\/\/www.anthropic.com\/news\/disrupting-AI-espionage\\\">https:\/\/www.anthropic.com\/news\/disrupting-AI-espionage<\/a> Accessed: 2026-05-27.\",\"id\":\"9a13a3ce-e43f-4456-95ad-80c993fe60e5\"},{\"content\":\"National Cyber Security Centre (NCSC). \\\"Defending Against China-Nexus Covert Networks of Compromised Devices.\\\" 2025. <a href=\\\"https:\/\/www.ncsc.gov.uk\/news\/defending-against-china-nexus-covert-networks-of-compromised-devices\\\">https:\/\/www.ncsc.gov.uk\/news\/defending-against-china-nexus-covert-networks-of-compromised-devices<\/a>. Accessed: 2026-05-27.\",\"id\":\"269d9bc5-94ea-4ddc-8d4a-240dc488fa9c\"},{\"content\":\"Zhang, Andy K., Neil Perry, Riya Dulepet, Joey Ji, Celeste Menders, Justin Lin, Eliot Jones, et al. \u201cCybench: A Framework for Evaluating Cybersecurity Capabilities and Risks of Language Models.\u201d <a href=\\\"https:\/\/proceedings.iclr.cc\/paper_files\/paper\/2025\/hash\/3e9412a9c1d93810ef3ef7825115016b-Abstract-Conference.html\\\">International Conference on Learning Representations<\/a> 2025.\",\"id\":\"2b581d30-63bf-4aec-99dd-864364f766b6\"},{\"content\":\"The 90% threshold was first crossed on the <a href=\\\"https:\/\/cybench.github.io\/\\\">public Cybench leaderboard<\/a> by Claude Opus 4.6, which was added at 93% unguided solved on a 37-problem subset on February 6, 2026. Later, Claude Mythos Preview reached 100% on a 35-problem subset (Anthropic. \\\"Claude Mythos Preview System Card.\\\" 2026. <a href=\\\"https:\/\/www-cdn.anthropic.com\/7624816413e9b4d2e3ba620c5a5e091b98b190a5\/Claude%20Mythos%20Preview%20System%20Card.pdf\\\">https:\/\/www-cdn.anthropic.com\/7624816413e9b4d2e3ba620c5a5e091b98b190a5\/Claude%20Mythos%20Preview%20System%20Card.pdf<\/a>, p. 49. Accessed: 2026-05-27.). Recent model evaluations, including Anthropic\u2019s Claude Mythos system card and OpenAI\u2019s GPT-5.3-Codex cybersecurity evaluation, suggest substantial progress towards AI-enabled exploit development capabilities, although whether the models fully satisfy our definition remains uncertain.\",\"id\":\"adf6bfc5-9713-4cd2-9528-dc97f3186e69\"}]"},"research_type":[4],"class_list":["post-2287","research","type-research","status-publish","has-post-thumbnail","hentry","research_type-working-paper"],"acf":[],"yoast_head":"<title>Forecasting AI Cyber Risks and Capabilities: Results of a 2025 Pilot Study &#8211; Forecasting Research Institute<\/title>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/forecastingresearch.org\/research\/ai-cyber-risks-capabilities\" \/>\n<meta property=\"og:locale\" content=\"en_US\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"Forecasting AI Cyber Risks and Capabilities: Results of a 2025 Pilot Study &#8211; Forecasting Research Institute\" \/>\n<meta property=\"og:description\" content=\"A pilot study investigating how AI capabilities may affect near-term cybersecurity risk, focusing on two high-impact cyberattack pathways: data-damaging worm attacks and cyberattacks against the U.S. electrical grid.\" \/>\n<meta property=\"og:url\" content=\"https:\/\/forecastingresearch.org\/research\/ai-cyber-risks-capabilities\" \/>\n<meta property=\"og:site_name\" content=\"Forecasting Research Institute\" \/>\n<meta property=\"article:modified_time\" content=\"2026-07-23T12:35:04+00:00\" \/>\n<meta property=\"og:image\" content=\"https:\/\/forecastingresearch.org\/wp-content\/uploads\/2026\/06\/illustration_Midjourney_AI-cyber.jpg\" \/>\n\t<meta property=\"og:image:width\" content=\"1376\" \/>\n\t<meta property=\"og:image:height\" content=\"864\" \/>\n\t<meta property=\"og:image:type\" content=\"image\/jpeg\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\\\/\\\/schema.org\",\"@graph\":[{\"@type\":\"WebPage\",\"@id\":\"https:\\\/\\\/forecastingresearch.org\\\/research\\\/ai-cyber-risks-capabilities\",\"url\":\"https:\\\/\\\/forecastingresearch.org\\\/research\\\/ai-cyber-risks-capabilities\",\"name\":\"Forecasting AI Cyber Risks and Capabilities: Results of a 2025 Pilot Study &#8211; Forecasting Research Institute\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/forecastingresearch.org\\\/#website\"},\"primaryImageOfPage\":{\"@id\":\"https:\\\/\\\/forecastingresearch.org\\\/research\\\/ai-cyber-risks-capabilities#primaryimage\"},\"image\":{\"@id\":\"https:\\\/\\\/forecastingresearch.org\\\/research\\\/ai-cyber-risks-capabilities#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/forecastingresearch.org\\\/wp-content\\\/uploads\\\/2026\\\/06\\\/illustration_Midjourney_AI-cyber.jpg\",\"datePublished\":\"2026-07-23T12:30:13+00:00\",\"dateModified\":\"2026-07-23T12:35:04+00:00\",\"breadcrumb\":{\"@id\":\"https:\\\/\\\/forecastingresearch.org\\\/research\\\/ai-cyber-risks-capabilities#breadcrumb\"},\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\\\/\\\/forecastingresearch.org\\\/research\\\/ai-cyber-risks-capabilities\"]}]},{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/forecastingresearch.org\\\/research\\\/ai-cyber-risks-capabilities#primaryimage\",\"url\":\"https:\\\/\\\/forecastingresearch.org\\\/wp-content\\\/uploads\\\/2026\\\/06\\\/illustration_Midjourney_AI-cyber.jpg\",\"contentUrl\":\"https:\\\/\\\/forecastingresearch.org\\\/wp-content\\\/uploads\\\/2026\\\/06\\\/illustration_Midjourney_AI-cyber.jpg\",\"width\":1376,\"height\":864},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\\\/\\\/forecastingresearch.org\\\/research\\\/ai-cyber-risks-capabilities#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"Home\",\"item\":\"https:\\\/\\\/forecastingresearch.org\\\/\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"Forecasting AI Cyber Risks and Capabilities: Results of a 2025 Pilot Study\"}]},{\"@type\":\"WebSite\",\"@id\":\"https:\\\/\\\/forecastingresearch.org\\\/#website\",\"url\":\"https:\\\/\\\/forecastingresearch.org\\\/\",\"name\":\"Forecasting Research Institute\",\"description\":\"\",\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\\\/\\\/forecastingresearch.org\\\/?s={search_term_string}\"},\"query-input\":{\"@type\":\"PropertyValueSpecification\",\"valueRequired\":true,\"valueName\":\"search_term_string\"}}],\"inLanguage\":\"en-US\"}]}<\/script>","yoast_head_json":{"title":"Forecasting AI Cyber Risks and Capabilities: Results of a 2025 Pilot Study &#8211; Forecasting Research Institute","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/forecastingresearch.org\/research\/ai-cyber-risks-capabilities","og_locale":"en_US","og_type":"article","og_title":"Forecasting AI Cyber Risks and Capabilities: Results of a 2025 Pilot Study &#8211; Forecasting Research Institute","og_description":"A pilot study investigating how AI capabilities may affect near-term cybersecurity risk, focusing on two high-impact cyberattack pathways: data-damaging worm attacks and cyberattacks against the U.S. electrical grid.","og_url":"https:\/\/forecastingresearch.org\/research\/ai-cyber-risks-capabilities","og_site_name":"Forecasting Research Institute","article_modified_time":"2026-07-23T12:35:04+00:00","og_image":[{"width":1376,"height":864,"url":"https:\/\/forecastingresearch.org\/wp-content\/uploads\/2026\/06\/illustration_Midjourney_AI-cyber.jpg","type":"image\/jpeg"}],"twitter_card":"summary_large_image","schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"WebPage","@id":"https:\/\/forecastingresearch.org\/research\/ai-cyber-risks-capabilities","url":"https:\/\/forecastingresearch.org\/research\/ai-cyber-risks-capabilities","name":"Forecasting AI Cyber Risks and Capabilities: Results of a 2025 Pilot Study &#8211; Forecasting Research Institute","isPartOf":{"@id":"https:\/\/forecastingresearch.org\/#website"},"primaryImageOfPage":{"@id":"https:\/\/forecastingresearch.org\/research\/ai-cyber-risks-capabilities#primaryimage"},"image":{"@id":"https:\/\/forecastingresearch.org\/research\/ai-cyber-risks-capabilities#primaryimage"},"thumbnailUrl":"https:\/\/forecastingresearch.org\/wp-content\/uploads\/2026\/06\/illustration_Midjourney_AI-cyber.jpg","datePublished":"2026-07-23T12:30:13+00:00","dateModified":"2026-07-23T12:35:04+00:00","breadcrumb":{"@id":"https:\/\/forecastingresearch.org\/research\/ai-cyber-risks-capabilities#breadcrumb"},"inLanguage":"en-US","potentialAction":[{"@type":"ReadAction","target":["https:\/\/forecastingresearch.org\/research\/ai-cyber-risks-capabilities"]}]},{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/forecastingresearch.org\/research\/ai-cyber-risks-capabilities#primaryimage","url":"https:\/\/forecastingresearch.org\/wp-content\/uploads\/2026\/06\/illustration_Midjourney_AI-cyber.jpg","contentUrl":"https:\/\/forecastingresearch.org\/wp-content\/uploads\/2026\/06\/illustration_Midjourney_AI-cyber.jpg","width":1376,"height":864},{"@type":"BreadcrumbList","@id":"https:\/\/forecastingresearch.org\/research\/ai-cyber-risks-capabilities#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https:\/\/forecastingresearch.org\/"},{"@type":"ListItem","position":2,"name":"Forecasting AI Cyber Risks and Capabilities: Results of a 2025 Pilot Study"}]},{"@type":"WebSite","@id":"https:\/\/forecastingresearch.org\/#website","url":"https:\/\/forecastingresearch.org\/","name":"Forecasting Research Institute","description":"","potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/forecastingresearch.org\/?s={search_term_string}"},"query-input":{"@type":"PropertyValueSpecification","valueRequired":true,"valueName":"search_term_string"}}],"inLanguage":"en-US"}]}},"_links":{"self":[{"href":"https:\/\/forecastingresearch.org\/api\/wp\/v2\/research\/2287","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/forecastingresearch.org\/api\/wp\/v2\/research"}],"about":[{"href":"https:\/\/forecastingresearch.org\/api\/wp\/v2\/types\/research"}],"version-history":[{"count":48,"href":"https:\/\/forecastingresearch.org\/api\/wp\/v2\/research\/2287\/revisions"}],"predecessor-version":[{"id":2494,"href":"https:\/\/forecastingresearch.org\/api\/wp\/v2\/research\/2287\/revisions\/2494"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/forecastingresearch.org\/api\/wp\/v2\/media\/2390"}],"wp:attachment":[{"href":"https:\/\/forecastingresearch.org\/api\/wp\/v2\/media?parent=2287"}],"wp:term":[{"taxonomy":"research_type","embeddable":true,"href":"https:\/\/forecastingresearch.org\/api\/wp\/v2\/research_type?post=2287"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}